2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14844HIGH7.5A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash ...
CVE-2019-14273MEDIUM5.3In SilverStripe assets 4.0, there is broken access control on files.
CVE-2019-14272MEDIUM5.4In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS.
CVE-2019-12617LOW2.7In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pol...
CVE-2019-16903MEDIUM5.3Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should b...
CVE-2019-16738MEDIUM5.3In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup...
CVE-2019-16901HIGH7.5Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x00000000...
CVE-2019-16900HIGH7.5Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.
CVE-2019-16899HIGH7.5In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfo...
CVE-2019-16253HIGH7.8The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacke...
CVE-2019-16892MEDIUM5.5In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the unco...
CVE-2019-16890MEDIUM5.4Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
CVE-2019-12717HIGH7.8A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an aut...
CVE-2019-12709MEDIUM6.7A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 900...
CVE-2019-12672MEDIUM6.8A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical ac...
CVE-2019-12671HIGH7.8A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on...
CVE-2019-12670MEDIUM6.7A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G...
CVE-2019-12669HIGH7.5A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Softwa...
CVE-2019-12668MEDIUM4.8A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote at...
CVE-2019-12667MEDIUM4.8A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to cond...
CVE-2019-12666MEDIUM6.7A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform dire...
CVE-2019-12665HIGH7.4A vulnerability in the HTTP client feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attac...
CVE-2019-12664HIGH7.5A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Inte...
CVE-2019-12663HIGH8.6A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Softwa...
CVE-2019-12662MEDIUM6.7A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now