2019 CVE Vulnerabilities

17,618 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-4575CRITICAL9.8IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injec...
CVE-2019-25065CRITICAL9.8A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown ...
CVE-2019-12351CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_print.php via an id parameter value with a trailing...
CVE-2019-12350CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in dl/dl_download.php via an id parameter value with a trail...
CVE-2019-12349CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in /admin/dl_sendsms.php via the id parameter.
CVE-2019-12254CRITICAL9.8In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to a...
CVE-2019-9564CRITICAL9.8A vulnerability in the authentication logic of Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to bypass login and co...
CVE-2019-12266CRITICAL9.8Stack-based Buffer Overflow vulnerability in Wyze Cam Pan v2, Cam v2, Cam v3 allows an attacker to run arbitrary code on...
CVE-2019-20082CRITICAL9.8ASUS RT-N53 3.0.0.4.376.3754 devices have a buffer overflow via a long lan_dns1_x or lan_dns2_x parameter to Advanced_LA...
CVE-2019-8703CRITICAL9.8This issue was addressed with improved entitlements. This issue is fixed in watchOS 6, tvOS 13, macOS Catalina 10.15, iO...
CVE-2019-8643CRITICAL9.8CVE-2019-8643: Arun Sharma of VMWare This issue is fixed in macOS Mojave 10.14. Description: A logic issue was addressed...
CVE-2019-16240CRITICAL9.1A Buffer Overflow and Information Disclosure issue exists in HP OfficeJet Pro Printers before 001.1937C, and HP PageWide...
CVE-2019-19810CRITICAL10Zoom Call Recording 6.3.1 from Eleveo is vulnerable to Java Deserialization attacks targeting the inbuilt RMI service. A...
CVE-2019-6288CRITICAL9.8Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /E...
CVE-2019-10095CRITICAL9.8bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpre...
CVE-2019-25052CRITICAL9.1In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptogr...
CVE-2019-20467CRITICAL9.8An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a...
CVE-2019-18906CRITICAL9.8A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server ...
CVE-2019-25029CRITICAL9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o...
CVE-2019-12348CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
CVE-2019-25042CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that t...
CVE-2019-25039CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that...
CVE-2019-25038CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes ...
CVE-2019-25035CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vul...
CVE-2019-25034CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. N...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now