2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4570MEDIUM5.3IBM Tivoli Netcool Impact 7.1.0 through 7.1.0.16 generates an error message that includes sensitive information about it...
CVE-2019-4569MEDIUM5.4IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.16 is vulnerable to cross-site scripting. This vulnerability allows user...
CVE-2019-4243MEDIUM4.4IBM SmartCloud Analytics 1.3.1 through 1.3.5 allows unauthorized disclosure of information like accessing solrconfig.xml...
CVE-2019-4216MEDIUM4.6IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to H...
CVE-2019-4215MEDIUM6.1IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to hijack the clicking action of the victim. ...
CVE-2019-4214LOW3.7IBM SmartCloud Analytics 1.3.1 through 1.3.5 does not set the secure attribute on authorization tokens or session cookie...
CVE-2019-3428MEDIUM6.5The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a configuration error vulnerability. An attacker coul...
CVE-2019-3427HIGH7.2The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exp...
CVE-2019-19013HIGH8.8A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a ...
CVE-2019-19227MEDIUM5.5In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because registe...
CVE-2019-10206MEDIUM6.5ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before...
CVE-2019-10203MEDIUM4.3PowerDNS Authoritative daemon , pdns versions 4.0.x before 4.0.9, 4.1.x before 4.1.11, exiting when encountering a seria...
CVE-2019-13157HIGH7.5nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences...
CVE-2019-19221MEDIUM5.5In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorre...
CVE-2019-18933CRITICAL9.8In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registere...
CVE-2019-18889CRITICAL9.8An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing cert...
CVE-2019-18888HIGH7.5An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4...
CVE-2019-18887HIGH8.1An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4...
CVE-2019-11325CRITICAL9.8An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes str...
CVE-2019-19207HIGH8.8rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVE-2019-19204HIGH7.5An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as ...
CVE-2019-19203HIGH7.5An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UCha...
CVE-2019-5637HIGH7.5When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached b...
CVE-2019-5636HIGH7.5When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi...
CVE-2019-19202HIGH8.8In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to c...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now