2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-5850CRITICAL9.6Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the ...
CVE-2019-18622CRITICAL9.8An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection...
CVE-2019-13566CRITICAL9.8An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3...
CVE-2019-18933CRITICAL9.8In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registere...
CVE-2019-18889CRITICAL9.8An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing cert...
CVE-2019-11325CRITICAL9.8An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes str...
CVE-2019-19033CRITICAL9.8Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges v...
CVE-2019-19006CRITICAL9.8Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CVE-2019-18349CRITICAL9.8HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp.
CVE-2019-5509CRITICAL9.8ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerabil...
CVE-2019-2303CRITICAL9.8SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdrag...
CVE-2019-2289CRITICAL9.8Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Sn...
CVE-2019-2271CRITICAL9.8Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values i...
CVE-2019-2268CRITICAL9.8Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consume...
CVE-2019-16541CRITICAL9.9Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions,...
CVE-2019-16340CRITICAL9.8Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for ...
CVE-2019-10627CRITICAL9.8Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp...
CVE-2019-18858CRITICAL9.8CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow.
CVE-2019-5541CRITICAL9.1VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in ...
CVE-2019-10765CRITICAL9.8iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.
CVE-2019-10766CRITICAL9.8Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sa...
CVE-2019-12409CRITICAL9.8The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration opt...
CVE-2019-12271CRITICAL9.8Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of addin...
CVE-2019-19113CRITICAL9.8main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCatego...
CVE-2019-17058CRITICAL9.1Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a w...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now