2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19341MEDIUM5.5A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab...
CVE-2019-19340HIGH8.2A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager b...
CVE-2019-19234HIGH7.5In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead...
CVE-2019-19232HIGH7.5In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invo...
CVE-2019-17527CRITICAL9.8dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Inje...
CVE-2019-16871CRITICAL9.8Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attack...
CVE-2019-8256CRITICAL9.8ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulner...
CVE-2019-8255CRITICAL9.8Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitra...
CVE-2019-8254HIGH7.8Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful ex...
CVE-2019-8253HIGH7.8Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful ex...
CVE-2019-11294MEDIUM4.3Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, i...
CVE-2019-19910MEDIUM6.1The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, a...
CVE-2019-19909HIGH8.8An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) ...
CVE-2019-18181HIGH7.8In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass...
CVE-2019-19907CRITICAL9.8HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demon...
CVE-2019-19906HIGH7.5cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in Ope...
CVE-2019-19905CRITICAL9.8NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration f...
CVE-2019-18955MEDIUM6.1The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed wit...
CVE-2019-18615MEDIUM4.9In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user pa...
CVE-2019-17633HIGH8.8For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could t...
CVE-2019-16465HIGH7.5Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v...
CVE-2019-16464CRITICAL9.8Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v...
CVE-2019-11780HIGH8.1Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 a...
CVE-2019-16463CRITICAL9.8Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v...
CVE-2019-16462CRITICAL9.8Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now