2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-18345CRITICAL9.3A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a use...
CVE-2019-16246CRITICAL9.8Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to...
CVE-2019-15936CRITICAL9.8Intesync Solismed 3.3sp allows Insecure File Upload.
CVE-2019-15933CRITICAL9.8Intesync Solismed 3.3sp has SQL Injection.
CVE-2019-15932CRITICAL9.8Intesync Solismed 3.3sp has Incorrect Access Control.
CVE-2019-15931CRITICAL9.8Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246.
CVE-2019-2320CRITICAL9.8Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd...
CVE-2019-10559CRITICAL9.8Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem...
CVE-2019-10511CRITICAL9.8Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdra...
CVE-2019-10493CRITICAL9.8Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput...
CVE-2019-19740CRITICAL9.8Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable.
CVE-2019-5093CRITICAL9.8An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so ...
CVE-2019-5085CRITICAL9.8An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, v...
CVE-2019-10694CRITICAL9.8The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the ins...
CVE-2019-3989CRITICAL9.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-0403CRITICAL9.8SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed whe...
CVE-2019-19374CRITICAL9.1An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_u...
CVE-2019-19725CRITICAL9.8sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.
CVE-2019-19649CRITICAL9.8Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServl...
CVE-2019-18960CRITICAL9.8Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitab...
CVE-2019-18935CRITICAL9.8Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp...
CVE-2019-17270CRITICAL9.8Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi...
CVE-2019-4521CRITICAL9.8Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could ...
CVE-2019-4244CRITICAL9.1IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestri...
CVE-2019-4621CRITICAL9.8IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account tha...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now