2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18184CRITICAL9.8Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
CVE-2019-10220HIGH8.8Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
CVE-2019-19308MEDIUM5.5In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing ...
CVE-2019-15300HIGH8.8A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Admin...
CVE-2019-15298HIGH8.8A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/c...
CVE-2019-14812HIGH7.8A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly...
CVE-2019-13936MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme...
CVE-2019-13935MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme...
CVE-2019-13934MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme...
CVE-2019-10216HIGH7.8In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scr...
CVE-2019-14896CRITICAL9.8A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr...
CVE-2019-14867HIGH8.8A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ...
CVE-2019-10195MEDIUM6.5A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ...
CVE-2019-17590HIGH8.8The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it al...
CVE-2019-17392CRITICAL9.8Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is...
CVE-2019-16388MEDIUM4.3PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAle...
CVE-2019-16387HIGH8.1PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li...
CVE-2019-16386MEDIUM4.3PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivi...
CVE-2019-16255HIGH8.1Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "c...
CVE-2019-16254MEDIUM5.3Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBr...
CVE-2019-16201HIGH7.5WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expressi...
CVE-2019-16195MEDIUM6.1Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields.
CVE-2019-18679HIGH7.5An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to in...
CVE-2019-18678MEDIUM5.3An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend ...
CVE-2019-18677MEDIUM6.1An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended ch...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now