2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13347HIGH7.5An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 ...
CVE-2019-19782CRITICAL9.8The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
CVE-2019-19778HIGH8.8An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c...
CVE-2019-19777HIGH8.8stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read i...
CVE-2019-16777MEDIUM6.5Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing glob...
CVE-2019-16776HIGH8.1Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders...
CVE-2019-16775MEDIUM6.5Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create...
CVE-2019-16774CRITICAL9.8In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
CVE-2019-12420HIGH7.5In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3...
CVE-2019-5144HIGH8.8An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Softw...
CVE-2019-5062MEDIUM6.5An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected c...
CVE-2019-5061MEDIUM6.5An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAP...
CVE-2019-3951CRITICAL9.8Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of ...
CVE-2019-19771HIGH8.8The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash p...
CVE-2019-19770HIGH8.2In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (whic...
CVE-2019-19769MEDIUM6.7In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include...
CVE-2019-19768HIGH7.5In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace...
CVE-2019-19767MEDIUM5.5The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_exp...
CVE-2019-19766HIGH7.5The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
CVE-2019-18342CRITICAL9.9A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po...
CVE-2019-18341MEDIUM5.3A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po...
CVE-2019-18340MEDIUM5.5A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) ...
CVE-2019-18339CRITICAL9.8A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port ...
CVE-2019-18338HIGH7.7A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (C...
CVE-2019-18337CRITICAL9.8A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (C...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now