2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-16948CRITICAL9.8An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at We...
CVE-2019-18839CRITICAL9FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attack...
CVE-2019-6188CRITICAL9.8The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p,...
CVE-2019-17330CRITICAL9.6The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow a...
CVE-2019-1449CRITICAL9.8A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially c...
CVE-2019-1384CRITICAL9.9A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messa...
CVE-2019-1373CRITICAL9.8A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShel...
CVE-2019-12719CRITICAL9.8An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an inc...
CVE-2019-0721CRITICAL9.1A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali...
CVE-2019-0719CRITICAL9.1A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali...
CVE-2019-18925CRITICAL9.8Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
CVE-2019-18655CRITICAL9.8File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera...
CVE-2019-18658CRITICAL9.8In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport...
CVE-2019-18873CRITICAL9FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An ...
CVE-2019-18852CRITICAL9.8Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign ...
CVE-2019-18623CRITICAL9.8Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic...
CVE-2019-18835CRITICAL9.8Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_le...
CVE-2019-18818CRITICAL9.8strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s...
CVE-2019-11996CRITICAL9.8Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurati...
CVE-2019-18814CRITICAL9.8An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_a...
CVE-2019-16872CRITICAL9.9Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4).
CVE-2019-18805CRITICAL9.8An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c...
CVE-2019-12419CRITICAL9.8Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Conn...
CVE-2019-5644CRITICAL9.8Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a...
CVE-2019-5617CRITICAL9.8Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now