2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-8135CRITICAL9.8A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. Dep...
CVE-2019-8121CRITICAL9.8An insecure component vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prio...
CVE-2019-18780CRITICAL9.8An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthentica...
CVE-2019-17211CRITICAL9.8An integer overflow was discovered in the CoAP library in Arm Mbed OS 5.14.0. The function sn_coap_builder_calc_needed_p...
CVE-2019-17212CRITICAL9.8Buffer overflows were discovered in the CoAP library in Arm Mbed OS 5.14.0. The CoAP parser is responsible for parsing r...
CVE-2019-18663CRITICAL9.8A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attack...
CVE-2019-18662CRITICAL9.8An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plu...
CVE-2019-18226CRITICAL9.8Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products ...
CVE-2019-13551CRITICAL9.8Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper valida...
CVE-2019-13547CRITICAL9.8Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. There is an unsecured function that allows anyone who can access the...
CVE-2019-13508CRITICAL9.8FreeTDS through 1.1.11 has a Buffer Overflow.
CVE-2019-5151CRITICAL9.8An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can...
CVE-2019-5049CRITICAL10An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15...
CVE-2019-18465CRITICAL9.8In Progress MOVEit Transfer 11.1 before 11.1.3, a vulnerability has been found that could allow an attacker to sign in w...
CVE-2019-18464CRITICAL9.8In Progress MOVEit Transfer 10.2 before 10.2.6 (2018.3), 11.0 before 11.0.4 (2019.0.4), and 11.1 before 11.1.3 (2019.1.3...
CVE-2019-18364CRITICAL9.8In JetBrains TeamCity before 2019.1.4, insecure Java Deserialization could potentially allow remote code execution.
CVE-2019-18425CRITICAL9.8An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installin...
CVE-2019-18633CRITICAL9.8European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain Exp...
CVE-2019-18632CRITICAL9.8European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a...
CVE-2019-10762CRITICAL9.8columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
CVE-2019-8287CRITICAL9.8TightVNC code version 1.3.10 contains global buffer overflow in HandleCoRREBBP macro function, which can potentially res...
CVE-2019-18624CRITICAL9.8Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (...
CVE-2019-18604CRITICAL9.8In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf i...
CVE-2019-15683CRITICAL9.8TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a53...
CVE-2019-15679CRITICAL9.8TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially re...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now