2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-4651CRITICAL9.8IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted ...
CVE-2019-9812CRITICAL9.3Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by ...
CVE-2019-19495CRITICAL9.8The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to...
CVE-2019-5082CRITICAL9.8An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 ...
CVE-2019-20367CRITICAL9.1nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (s...
CVE-2019-10777CRITICAL9.8In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within th...
CVE-2019-19518CRITICAL9.8CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server ...
CVE-2019-17076CRITICAL9.8An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in ...
CVE-2019-10778CRITICAL9.8devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the ex...
CVE-2019-20361CRITICAL9.8There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b...
CVE-2019-17146CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07....
CVE-2019-14906CRITICAL9.8A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue ...
CVE-2019-10776CRITICAL9.8In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. ...
CVE-2019-14837CRITICAL9.1A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this ...
CVE-2019-16273CRITICAL9.8DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading ...
CVE-2019-16272CRITICAL9.8On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enab...
CVE-2019-18792CRITICAL9.1An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP s...
CVE-2019-20343CRITICAL9.8The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration ...
CVE-2019-15976CRITICAL9.8Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an una...
CVE-2019-15975CRITICAL9.8Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an una...
CVE-2019-19628CRITICAL9.8In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry...
CVE-2019-11994CRITICAL9.8A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 ...
CVE-2019-19088CRITICAL9.8Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal.
CVE-2019-20330CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-14859CRITICAL9.1A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used D...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now