2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13327HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13326HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13325HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2019-13324HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2019-13323HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6...
CVE-2019-11932HIGH8.8A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version ...
CVE-2019-16198MEDIUM6.5KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter.
CVE-2019-15766HIGH8.8The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POS...
CVE-2019-17110Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-10223. Reason: This candidate is a duplicate of ...
CVE-2019-16328HIGH7.5In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure ...
CVE-2019-16931MEDIUM6.1A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar...
CVE-2019-16866HIGH7.5Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIF...
CVE-2019-15165MEDIUM5.3sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
CVE-2019-15164MEDIUM5.3rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
CVE-2019-15163HIGH7.5rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daem...
CVE-2019-15162MEDIUM5.3rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which...
CVE-2019-15161MEDIUM5.3rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open u...
CVE-2019-15166HIGH7.5lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
CVE-2019-4441MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive infor...
CVE-2019-4422HIGH8.8IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated use...
CVE-2019-3834HIGH7.3It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows atta...
CVE-2019-15809MEDIUM4.7Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timi...
CVE-2019-13629MEDIUM5.9MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remot...
CVE-2019-13628MEDIUM4.7wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) conta...
CVE-2019-11651MEDIUM6.1Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now