2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17555HIGH7.5The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it t...
CVE-2019-7201HIGH7.8An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul...
CVE-2019-7197MEDIUM4.8A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, th...
CVE-2019-19555MEDIUM5.5read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf.
CVE-2019-17556CRITICAL9.8Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and...
CVE-2019-17554MEDIUM5.5The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti...
CVE-2019-11940CRITICAL9.8In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations...
CVE-2019-11936CRITICAL9.8Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue a...
CVE-2019-11935CRITICAL9.8Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This iss...
CVE-2019-11934CRITICAL9.8Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly...
CVE-2019-11930CRITICAL9.8An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. Th...
CVE-2019-11937HIGH7.5In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhausti...
CVE-2019-11923HIGH7.5In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no max...
CVE-2019-15638HIGH7.8COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
CVE-2019-14909HIGH8.3A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any pa...
CVE-2019-18850HIGH7.5TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding ...
CVE-2019-5164HIGH7.8An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafte...
CVE-2019-5163HIGH7.5An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti...
CVE-2019-5133HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library....
CVE-2019-5132HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear...
CVE-2019-5112HIGH8.8Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server....
CVE-2019-5111HIGH8.8Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server....
CVE-2019-5110HIGH8.8Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web r...
CVE-2019-5109HIGH8.8Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web ...
CVE-2019-5097HIGH7.5A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web serv...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now