2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-0688An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, a...
CVE-2019-0685An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2019-7361An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trig...
CVE-2019-7360An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Au...
CVE-2019-7359An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk Au...
CVE-2019-7358An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Aut...
CVE-2019-5513VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosu...
CVE-2019-5512VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately...
CVE-2019-5511VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Succ...
CVE-2019-1567The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ...
CVE-2019-7174Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), f...
CVE-2019-6117The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function.
CVE-2019-3941Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
CVE-2019-3940Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote ...
CVE-2019-10244In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and t...
CVE-2019-10243In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used...
CVE-2019-10242In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially a...
CVE-2019-11028GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to...
CVE-2019-10634An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitr...
CVE-2019-10633An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a re...
CVE-2019-10632A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a l...
CVE-2019-10631Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated a...
CVE-2019-10630A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin...
CVE-2019-10902In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting s...
CVE-2019-10900In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c b...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now