2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-16338HIGH7.8The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
CVE-2019-16337HIGH7.8The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
CVE-2019-16067HIGH7.5NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web appli...
CVE-2019-16066HIGH8.8An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 an...
CVE-2019-16065HIGH8.8A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a...
CVE-2019-16061HIGH8.8A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable pe...
CVE-2019-15656HIGH7.5D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques...
CVE-2019-15655HIGH7.5D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to ...
CVE-2019-15654HIGH7.5Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download...
CVE-2019-15653HIGH7.5Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism....
CVE-2019-11361HIGH8.8Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala...
CVE-2019-16012HIGH8.1A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to...
CVE-2019-18979HIGH7.8Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation u...
CVE-2019-3762HIGH7.5Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulner...
CVE-2019-20529HIGH7.5In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were b...
CVE-2019-18582HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-18581HIGH7.2Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat...
CVE-2019-12769HIGH8.8SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forg...
CVE-2019-12123HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an auth...
CVE-2019-12121HIGH7.5An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSi...
CVE-2019-12113HIGH8.8An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authe...
CVE-2019-19355HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a...
CVE-2019-19351HIGH7An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker...
CVE-2019-11689HIGH8.1An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-11688HIGH7.4An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now