2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5096CRITICAL9.8An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go...
CVE-2019-5083HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft I...
CVE-2019-5076HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG header-parser of the Accusoft ImageGear...
CVE-2019-3750MEDIUM5.5Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici...
CVE-2019-3749MEDIUM5.5Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici...
CVE-2019-19543HIGH7.8In the Linux kernel before 5.1.6, there is a use-after-free in serial_ir_init_module() in drivers/media/rc/serial_ir.c.
CVE-2019-18574MEDIUM4.8RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the ...
CVE-2019-9689HIGH7.5process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certi...
CVE-2019-19459CRITICAL9.8An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as...
CVE-2019-19458HIGH8.6SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
CVE-2019-19457MEDIUM5.4SALTO ProAccess SPACE 5.4.3.0 allows XSS.
CVE-2019-19383HIGH8.8freeFTPd 1.0.8 has a Post-Authentication Buffer Overflow via a crafted SIZE command (this is exploitable even if logging...
CVE-2019-19382HIGH7.8Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replac...
CVE-2019-18993MEDIUM5.4OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI...
CVE-2019-18992MEDIUM5.4OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on ro...
CVE-2019-16885CRITICAL9.8In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP obj...
CVE-2019-13456MEDIUM6.5In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element canno...
CVE-2019-10013HIGH7.5The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows rem...
CVE-2019-19460MEDIUM5.5An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local S...
CVE-2019-7366HIGH7.8Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into openin...
CVE-2019-7365HIGH7.8DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a use...
CVE-2019-3990MEDIUM4.3A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed t...
CVE-2019-19537MEDIUM4.2In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB...
CVE-2019-19536MEDIUM4.6In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/...
CVE-2019-19535MEDIUM4.6In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now