2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-10158CRITICAL9.8A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protecti...
CVE-2019-3984CRITICAL9.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-7162CRITICAL9.1An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthentic...
CVE-2019-7478CRITICAL9.8A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS...
CVE-2019-13445CRITICAL9.8An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3...
CVE-2019-19735CRITICAL9.1class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes ...
CVE-2019-17621CRITICAL9.8The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem...
CVE-2019-10774CRITICAL9.8php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arb...
CVE-2019-16535CRITICAL9.8In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can...
CVE-2019-20049CRITICAL9.8An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a director...
CVE-2019-19781CRITICAL9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th...
CVE-2019-20041CRITICAL9.8wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing...
CVE-2019-19398CRITICAL9.8M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validat...
CVE-2019-16327CRITICAL9.8D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the se...
CVE-2019-19977CRITICAL9.8libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as ...
CVE-2019-10758CRITICAL9.9mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse...
CVE-2019-19953CRITICAL9.1In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders...
CVE-2019-19952CRITICAL9.8In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to R...
CVE-2019-19951CRITICAL9.8In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of cod...
CVE-2019-19950CRITICAL9.8In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magi...
CVE-2019-19949CRITICAL9.1In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, relat...
CVE-2019-19948CRITICAL9.8In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.
CVE-2019-12568CRITICAL9.8Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attacke...
CVE-2019-12567CRITICAL9.8Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attacke...
CVE-2019-8293CRITICAL9.8Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now