2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16748CRITICAL9.8In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while han...
CVE-2019-16746CRITICAL9.8An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of va...
CVE-2019-16729HIGH7.8pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all...
CVE-2019-16728MEDIUM6.1DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demo...
CVE-2019-10755MEDIUM4.9The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils...
CVE-2019-10754HIGH8.1Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for...
CVE-2019-1367HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2019-1255HIGH7.5A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denia...
CVE-2019-11277HIGH8.1Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP ...
CVE-2019-15635MEDIUM4.9An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An...
CVE-2019-16377CRITICAL9.8The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.
CVE-2019-12407MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10996HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-10990MEDIUM6.5Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to...
CVE-2019-10984HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-10978HIGH7.8Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie...
CVE-2019-10090MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-16723MEDIUM4.3In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_jso...
CVE-2019-16518MEDIUM4.3An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an...
CVE-2019-13063HIGH7.5Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc...
CVE-2019-12404MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10089MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-10087MEDIUM6.1On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit...
CVE-2019-3416CRITICAL9.8All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp...
CVE-2019-16722CRITICAL9.8ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now