2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19746MEDIUM5.5make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer o...
CVE-2019-19740CRITICAL9.8Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CVE-2019-19726HIGH7.8OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be...
CVE-2019-7004MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthoriz...
CVE-2019-5154HIGH8.8An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A s...
CVE-2019-5093CRITICAL9.8An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so ...
CVE-2019-5092HIGH8.8An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image form...
CVE-2019-5091HIGH7.5An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so...
CVE-2019-5090HIGH7.5An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltd...
CVE-2019-5085CRITICAL9.8An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, v...
CVE-2019-10695MEDIUM6.5When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s us...
CVE-2019-10694CRITICAL9.8The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the ins...
CVE-2019-3989CRITICAL9.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3988HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3987HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3986HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3985HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3983MEDIUM6.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the de...
CVE-2019-18245HIGH7.8Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th...
CVE-2019-18232HIGH7.8SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulne...
CVE-2019-17087HIGH7.5Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be e...
CVE-2019-0405HIGH7.5SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con...
CVE-2019-0404HIGH7.5SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading...
CVE-2019-0403CRITICAL9.8SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed whe...
CVE-2019-0402MEDIUM4.4SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive informati...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now