2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18601HIGH7.5OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote ...
CVE-2019-16647HIGH7.2Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
CVE-2019-15683CRITICAL9.8TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a53...
CVE-2019-15681HIGH7.5LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which...
CVE-2019-15680HIGH7.5TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System...
CVE-2019-15679CRITICAL9.8TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially re...
CVE-2019-15678CRITICAL9.8TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result cod...
CVE-2019-13066MEDIUM6.1Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable...
CVE-2019-10749CRITICAL9.8sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly...
CVE-2019-10748CRITICAL9.8Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not bei...
CVE-2019-10743MEDIUM5.5All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited usin...
CVE-2019-10211CRITICAL9.8Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu...
CVE-2019-10210HIGH7Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing pas...
CVE-2019-10209LOW2.2Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan.
CVE-2019-10208HIGH8.8A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before ...
CVE-2019-0210HIGH7.5In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when f...
CVE-2019-0205HIGH7.5In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with...
CVE-2019-4600MEDIUM5.3IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially cra...
CVE-2019-4546HIGH8.8After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges th...
CVE-2019-4339HIGH7.5IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could a...
CVE-2019-4330MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions...
CVE-2019-4329MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows ...
CVE-2019-4314HIGH7.5IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource tha...
CVE-2019-4311MEDIUM5.3IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The info...
CVE-2019-4309MEDIUM5.5IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to o...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now