2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-16066HIGH8.8An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 an...
CVE-2019-16065HIGH8.8A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a...
CVE-2019-16061HIGH8.8A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable pe...
CVE-2019-15656HIGH7.5D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques...
CVE-2019-15655HIGH7.5D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to ...
CVE-2019-15654HIGH7.5Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download...
CVE-2019-15653HIGH7.5Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism....
CVE-2019-11361HIGH8.8Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala...
CVE-2019-16012HIGH8.1A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to...
CVE-2019-18979HIGH7.8Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation u...
CVE-2019-3762HIGH7.5Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulner...
CVE-2019-20529HIGH7.5In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were b...
CVE-2019-18582HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-18581HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-12769HIGH8.8SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forg...
CVE-2019-12123HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an auth...
CVE-2019-12121HIGH7.5An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSi...
CVE-2019-12113HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authe...
CVE-2019-19355HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a...
CVE-2019-19351HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker...
CVE-2019-11689HIGH8.1An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-11688HIGH7.4An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-10682HIGH7.5django-nopassword before 5.0.0 stores cleartext secrets in the database.
CVE-2019-11939HIGH7.5Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the pay...
CVE-2019-20492HIGH8.8cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now