2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19034HIGH7.2Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username ...
CVE-2019-5186HIGH7An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit...
CVE-2019-5185HIGH7An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit...
CVE-2019-5184HIGH7.8An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A spe...
CVE-2019-18936HIGH7.5UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches ...
CVE-2019-17185HIGH7.5In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. Th...
CVE-2019-16528HIGH7.5An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attacker...
CVE-2019-19324HIGH7.5Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted a...
CVE-2019-15665HIGH7.2An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida...
CVE-2019-15075HIGH7.5An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have ...
CVE-2019-15661HIGH7.2An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida...
CVE-2019-14855HIGH7.5A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An att...
CVE-2019-19345HIGH7.8A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification v...
CVE-2019-19487HIGH8.8Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection ...
CVE-2019-19029HIGH7.2Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Har...
CVE-2019-19025HIGH8.8Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry fo...
CVE-2019-19023HIGH8.8Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware...
CVE-2019-18785HIGH7.5SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
CVE-2019-16108HIGH7.5phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
CVE-2019-16071HIGH8.8Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability t...
CVE-2019-16068HIGH8.8A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri...
CVE-2019-16063HIGH7.5NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an atta...
CVE-2019-16338HIGH7.8The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
CVE-2019-16337HIGH7.8The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
CVE-2019-16067HIGH7.5NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web appli...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now