2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-18609CRITICAL9.8An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that...
CVE-2019-19391CRITICAL9.1In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue th...
CVE-2019-14901CRITICAL9.8A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri...
CVE-2019-14897CRITICAL9.8A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An atta...
CVE-2019-14895CRITICAL9.8A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell ...
CVE-2019-18253CRITICAL10An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (vers...
CVE-2019-6665CRITICAL9.4On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow ...
CVE-2019-19330CRITICAL9.8The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd...
CVE-2019-18184CRITICAL9.8Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.
CVE-2019-14896CRITICAL9.8A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr...
CVE-2019-17392CRITICAL9.8Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is...
CVE-2019-18580CRITICAL10Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerabil...
CVE-2019-12526CRITICAL9.8An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. W...
CVE-2019-12523CRITICAL9.1An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTT...
CVE-2019-19307CRITICAL9.8An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infin...
CVE-2019-14842CRITICAL9.8Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check...
CVE-2019-6675CRITICAL9.8BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multip...
CVE-2019-12489CRITICAL9.8An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_re...
CVE-2019-15958CRITICAL9.8A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM)...
CVE-2019-18250CRITICAL9.8In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable...
CVE-2019-19250CRITICAL9.8OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
CVE-2019-19249CRITICAL9.8Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
CVE-2019-18374CRITICAL9.8Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypa...
CVE-2019-5870CRITICAL9.6Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbo...
CVE-2019-5866CRITICAL9.8Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potential...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now