2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16243MEDIUM6.1On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an undocumented web API that allows unprivileged JavaScript, in...
CVE-2019-16242MEDIUM6.8On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, there is an engineering application named omamock that is vulnerable to ...
CVE-2019-16241MEDIUM6.8On TCL Alcatel Cingular Flip 2 B9HUAH1 devices, PIN authentication can be bypassed by creating a special file within the...
CVE-2019-15688MEDIUM6.1Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15687MEDIUM6.5Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15686MEDIUM4.3Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-15685MEDIUM4.3Kaspersky Anti-Virus, Kaspersky Internet Security, Kaspersky Total Security, Kaspersky Free Anti-Virus, Kaspersky Small ...
CVE-2019-14842CRITICAL9.8Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check...
CVE-2019-6675CRITICAL9.8BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multip...
CVE-2019-19306MEDIUM5.4The Zoho CRM Lead Magnet plugin 1.6.9.1 for WordPress allows XSS via module, EditShortcode, or LayoutName.
CVE-2019-19275HIGH7.5typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python in...
CVE-2019-19274HIGH7.5typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Pyth...
CVE-2019-19206MEDIUM5.4Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile ...
CVE-2019-18463MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of...
CVE-2019-18462MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.
CVE-2019-18461MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a...
CVE-2019-18460HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature prov...
CVE-2019-12489CRITICAL9.8An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_re...
CVE-2019-14856MEDIUM6.5ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
CVE-2019-14853HIGH7.5An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatu...
CVE-2019-14857MEDIUM6.1A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes...
CVE-2019-14890HIGH8.4A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames an...
CVE-2019-19272HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable init...
CVE-2019-19271HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a clie...
CVE-2019-19270HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now