2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12674HIGH8.2Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an a...
CVE-2019-12673HIGH7.5A vulnerability in the FTP inspection engine of Cisco Adaptive Security (ASA) Software and Cisco Firepower Threat Defens...
CVE-2019-12631MEDIUM6.1A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an unauthenticated, re...
CVE-2019-12630CRITICAL9.8A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo...
CVE-2019-12157CRITICAL9.8In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
CVE-2019-12156MEDIUM5.3Server metadata could be exposed because one of the error messages reflected the whole response back to the client in Je...
CVE-2019-11929CRITICAL9.8Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, ...
CVE-2019-10212CRITICAL9.8A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attack...
CVE-2019-8462HIGH7.5In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management cras...
CVE-2019-13658CRITICAL9.8CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to exec...
CVE-2019-5031HIGH8.8An exploitable memory corruption vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader, ver...
CVE-2019-16116MEDIUM4.3EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file....
CVE-2019-13343HIGH7.5Butor Portal before 1.0.27 is affected by a Path Traversal vulnerability leading to a pre-authentication arbitrary file ...
CVE-2019-4549MEDIUM5.3IBM Security Directory Server 6.4.0 discloses sensitive information to unauthorized users. The information can be used t...
CVE-2019-4542MEDIUM6.1IBM Security Directory Server 6.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2019-4539HIGH7.1IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used in XML, allowing attacke...
CVE-2019-4538HIGH8.2IBM Security Directory Server 6.4.0 could allow a remote attacker to conduct phishing attacks, using an open redirect at...
CVE-2019-4520HIGH7.5IBM Security Directory Server 6.4.0 uses an inadequate account lockout setting that could allow a remote attacker to bru...
CVE-2019-13025CRITICAL9.8Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Valida...
CVE-2019-17091MEDIUM6.1faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Moja...
CVE-2019-17080HIGH7.8mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by a...
CVE-2019-14454CRITICAL9.8SuiteCRM 7.11.x and 7.10.x before 7.11.8 and 7.10.20 is vulnerable to vertical privilege escalation.
CVE-2019-13335CRITICAL9.8SalesAgility SuiteCRM 7.10.x 7.10.19 and 7.11.x before and 7.11.7 has SSRF.
CVE-2019-17075HIGH7.5An issue was discovered in write_tpt_entry in drivers/infiniband/hw/cxgb4/mem.c in the Linux kernel through 5.3.2. The c...
CVE-2019-8292MEDIUM5.3Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now