2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9757HIGH7.5An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-...
CVE-2019-8287CRITICAL9.8TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially res...
CVE-2019-6851HIGH7.5A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium ,...
CVE-2019-6850HIGH7.5A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic...
CVE-2019-6849HIGH7.5A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic...
CVE-2019-6848HIGH8.6A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M5...
CVE-2019-6847MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6846MEDIUM6.5A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon B...
CVE-2019-6845HIGH7.5A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon P...
CVE-2019-6844MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6843MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior...
CVE-2019-6842MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modicon BMxCR...
CVE-2019-6841MEDIUM4.9A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 with firmware (version prior...
CVE-2019-5533MEDIUM4.3In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mist...
CVE-2019-3979HIGH7.5RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router a...
CVE-2019-3978HIGH7.5RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri...
CVE-2019-3977HIGH7.5RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download...
CVE-2019-3976HIGH8.8RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerabi...
CVE-2019-18624CRITICAL9.8Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (...
CVE-2019-18612MEDIUM5.3An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Previously hidden (restricted) AbuseFil...
CVE-2019-18611MEDIUM6.5An issue was discovered in the CheckUser extension through 1.34 for MediaWiki. Certain sensitive information within over...
CVE-2019-18608HIGH7.5Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritte...
CVE-2019-18604CRITICAL9.8In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf i...
CVE-2019-18603MEDIUM5.9OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because unini...
CVE-2019-18602HIGH7.5OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now