2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-15678CRITICAL9.8TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result cod...
CVE-2019-10749CRITICAL9.8sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly...
CVE-2019-10748CRITICAL9.8Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not bei...
CVE-2019-10211CRITICAL9.8Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu...
CVE-2019-18189CRITICAL9.8A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5...
CVE-2019-17181CRITICAL9.8A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET o...
CVE-2019-14450CRITICAL9.8A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows...
CVE-2019-16897CRITICAL9.8In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Securi...
CVE-2019-11043CRITICAL9.8In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it ...
CVE-2019-14931CRITICAL9.8An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3...
CVE-2019-14930CRITICAL9.8An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3...
CVE-2019-14929CRITICAL9.8An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3...
CVE-2019-14926CRITICAL9.8An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3...
CVE-2019-16662CRITICAL9.8An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a...
CVE-2019-5129CRITICAL9.8A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the...
CVE-2019-5128CRITICAL9.8A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the...
CVE-2019-5127CRITICAL9.8A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the...
CVE-2019-5114CRITICAL9.9An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web ...
CVE-2019-13553CRITICAL9.8Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mech...
CVE-2019-16265CRITICAL9.8CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow.
CVE-2019-14451CRITICAL9.8RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when u...
CVE-2019-8088CRITICAL9.8Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation ...
CVE-2019-18418CRITICAL9.8clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be...
CVE-2019-18413CRITICAL9.8In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can...
CVE-2019-15929CRITICAL9.8In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, lea...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now