2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0050HIGH7.5Under certain heavy traffic conditions srxpfe process can crash and result in a denial of service condition for the SRX1...
CVE-2019-0047HIGH8.8A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attac...
CVE-2019-5507MEDIUM5.5SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited cou...
CVE-2019-5506MEDIUM5.9Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making the...
CVE-2019-17402MEDIUM6.5Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffD...
CVE-2019-17401LOW3.3libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_locati...
CVE-2019-17092MEDIUM6.1An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to injec...
CVE-2019-17399CRITICAL9.8The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
CVE-2019-17389HIGH7.5In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP sock...
CVE-2019-6471MEDIUM5.9A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion...
CVE-2019-6469HIGH7.5An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failur...
CVE-2019-6468HIGH7.5In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Cl...
CVE-2019-6467HIGH7.5A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespac...
CVE-2019-6465MEDIUM5.3Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable V...
CVE-2019-4558HIGH7.8A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spect...
CVE-2019-4512MEDIUM4.3IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in...
CVE-2019-3653MEDIUM5.5Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 20...
CVE-2019-3652MEDIUM5.3Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows...
CVE-2019-17385MEDIUM6.1The animate-it plugin before 2.3.5 for WordPress has XSS.
CVE-2019-17384MEDIUM6.1The animate-it plugin before 2.3.4 for WordPress has XSS.
CVE-2019-17383CRITICAL9.8The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 per...
CVE-2019-17380MEDIUM6.1cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
CVE-2019-17379MEDIUM6.1cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527).
CVE-2019-17378MEDIUM6.1cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526).
CVE-2019-17377MEDIUM6.1cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524).

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now