2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9531CRITICAL9.8The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454...
CVE-2019-9530MEDIUM5.5The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and ...
CVE-2019-9529MEDIUM5.5The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou...
CVE-2019-15051HIGH8.8An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to co...
CVE-2019-11528HIGH7.5An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.
CVE-2019-11527HIGH8.8An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously...
CVE-2019-14810MEDIUM5.9A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under rac...
CVE-2019-11526CRITICAL9.8An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable t...
CVE-2019-17455CRITICAL9.8Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthRespon...
CVE-2019-5535MEDIUM4.7VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6...
CVE-2019-5527HIGH8.8ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. V...
CVE-2019-17454MEDIUM6.5Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom...
CVE-2019-17453MEDIUM6.5Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP...
CVE-2019-17452MEDIUM6.5Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to...
CVE-2019-17451MEDIUM6.5An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. I...
CVE-2019-17450MEDIUM6.5find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binut...
CVE-2019-17449MEDIUM6.7Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerabil...
CVE-2019-17320CRITICAL9.8NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary ch...
CVE-2019-4265LOW2.4IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker...
CVE-2019-1378HIGH7.8An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locall...
CVE-2019-1376MEDIUM6.5An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor...
CVE-2019-1375MEDIUM5.4A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci...
CVE-2019-1372CRITICAL10An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length o...
CVE-2019-1371HIGH7.5A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet...
CVE-2019-1369MEDIUM5.5An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now