2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18663CRITICAL9.8A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attack...
CVE-2019-18178HIGH7.5Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file...
CVE-2019-17210HIGH7.5A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString()...
CVE-2019-13497MEDIUM6.5One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests.
CVE-2019-13496HIGH8.1One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the...
CVE-2019-18684HIGH7Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo pr...
CVE-2019-18683HIGH7An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile...
CVE-2019-18680HIGH7.5An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_so...
CVE-2019-0350HIGH7.5SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which cras...
CVE-2019-18673MEDIUM4.6On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-ba...
CVE-2019-14360MEDIUM4.6On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of ...
CVE-2019-14358MEDIUM4.6On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-bas...
CVE-2019-18668MEDIUM6.5An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that ...
CVE-2019-18667MEDIUM6.1/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a use...
CVE-2019-18665HIGH7.5The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion.
CVE-2019-18664MEDIUM5.4The Log module in SECUDOS DOMOS before 5.6 allows XSS.
CVE-2019-18662CRITICAL9.8An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plu...
CVE-2019-18661HIGH7.5Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 ...
CVE-2019-18659MEDIUM5.3The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic...
CVE-2019-6470HIGH7.5There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 m...
CVE-2019-18654MEDIUM6.1A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in ...
CVE-2019-18653MEDIUM6.1A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 b...
CVE-2019-12752MEDIUM6.1The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which coul...
CVE-2019-6658MEDIUM4.3On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration...
CVE-2019-6657MEDIUM6.1On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exis...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now