2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-4676HIGH7.8IBM Security Identity Manager Virtual Appliance 7.0.2 stores user credentials in plain in clear text which can be read b...
CVE-2019-19163HIGH8.8A Vulnerability in the firmware of COMMAX WallPad(CDP-1020MB) allow an unauthenticated adjacent attacker to execute arbi...
CVE-2019-19161HIGH7.2CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in download...
CVE-2019-19160HIGH8.8Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th...
CVE-2019-20413HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili...
CVE-2019-19506HIGH7.5Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" ...
CVE-2019-19505HIGH8.8Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds ch...
CVE-2019-16213HIGH8.8Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on...
CVE-2019-14894HIGH7.2A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere...
CVE-2019-14094HIGH7.8Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet ...
CVE-2019-14091HIGH7.8Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdrago...
CVE-2019-14076HIGH7.8Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Sn...
CVE-2019-14047HIGH7.8While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to...
CVE-2019-10597HIGH7.8kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdrago...
CVE-2019-20891HIGH8.8WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with re...
CVE-2019-20888HIGH7.5An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial...
CVE-2019-20886HIGH7.5An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin.
CVE-2019-20885HIGH7.5An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file.
CVE-2019-20881HIGH7.3An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA.
CVE-2019-20880HIGH7.5An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a deni...
CVE-2019-20874HIGH7.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi...
CVE-2019-20871HIGH7.5An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastr...
CVE-2019-20868HIGH7.5An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated.
CVE-2019-20865HIGH8.8An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CS...
CVE-2019-20864HIGH7.5An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now