2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12661MEDIUM6.7A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authentic...
CVE-2019-12660MEDIUM5.5A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to write values to the ...
CVE-2019-12659HIGH7.5A vulnerability in the HTTP server code of Cisco IOS XE Software could allow an unauthenticated, remote attacker to caus...
CVE-2019-12658HIGH7.5A vulnerability in the filesystem resource management code of Cisco IOS XE Software could allow an unauthenticated, remo...
CVE-2019-12657HIGH7.5A vulnerability in Unified Threat Defense (UTD) in Cisco IOS XE Software could allow an unauthenticated, remote attacker...
CVE-2019-12656HIGH7.5A vulnerability in the IOx application environment of multiple Cisco platforms could allow an unauthenticated, remote at...
CVE-2019-12655HIGH7.5A vulnerability in the FTP application layer gateway (ALG) functionality used by Network Address Translation (NAT), NAT ...
CVE-2019-12654HIGH7.5A vulnerability in the common Session Initiation Protocol (SIP) library of Cisco IOS and IOS XE Software could allow an ...
CVE-2019-12653HIGH7.5A vulnerability in the Raw Socket Transport feature of Cisco IOS XE Software could allow an unauthenticated, remote atta...
CVE-2019-12652HIGH7.5A vulnerability in the ingress packet processing function of Cisco IOS Software for Cisco Catalyst 4000 Series Switches ...
CVE-2019-6656HIGH7.5BIG-IP APM Edge Client before version 7.1.8 (7180.2019.508.705) logs the full apm session ID in the log files. Vulnerabl...
CVE-2019-4571MEDIUM5.4IBM Content Navigator 3.0CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2019-16889HIGH7.5Ubiquiti EdgeMAX devices before 2.0.3 allow remote attackers to cause a denial of service (disk consumption) because *.c...
CVE-2019-15941CRITICAL9.8OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a craf...
CVE-2019-14666HIGH8.8GLPI through 9.4.3 is prone to account takeover by abusing the ajax/autocompletion.php autocompletion feature. The lack ...
CVE-2019-12651HIGH8.8Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated,...
CVE-2019-12650HIGH8.8Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated,...
CVE-2019-12649MEDIUM6.7A vulnerability in the Image Verification feature of Cisco IOS XE Software could allow an authenticated, local attacker ...
CVE-2019-12648HIGH8.8A vulnerability in the IOx application environment for Cisco IOS Software could allow an authenticated, remote attacker ...
CVE-2019-12647HIGH7.5A vulnerability in the Ident protocol handler of Cisco IOS and IOS XE Software could allow an unauthenticated, remote at...
CVE-2019-12646HIGH7.5A vulnerability in the Network Address Translation (NAT) Session Initiation Protocol (SIP) Application Layer Gateway (AL...
CVE-2019-6655MEDIUM5.3On versions 13.0.0-13.1.0.1, 12.1.0-12.1.4.1, 11.6.1-11.6.4, and 11.5.1-11.5.9, BIG-IP platforms where AVR, ASM, APM, PE...
CVE-2019-6654MEDIUM4.3On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian A...
CVE-2019-15069CRITICAL9.8An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware vers...
CVE-2019-15068CRITICAL9.8A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now