2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-20490HIGH8.8cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
CVE-2019-11074HIGH7.2A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attacke...
CVE-2019-20453HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20452HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20326HIGH7.8A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg....
CVE-2019-20191HIGH7.5Oxygen XML Editor 21.1.1 allows XXE to read any file.
CVE-2019-19538HIGH7.2In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command...
CVE-2019-19937HIGH7.2In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user i...
CVE-2019-11073HIGH7.2A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut...
CVE-2019-5543HIGH7.8For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0....
CVE-2019-19945HIGH7.5uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou...
CVE-2019-19821HIGH8.1A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to ...
CVE-2019-19942HIGH7.5Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10....
CVE-2019-19940HIGH7.2Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allow...
CVE-2019-19135HIGH7.4In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun...
CVE-2019-19209HIGH7.5Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2019-10091HIGH7.4When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verific...
CVE-2019-17654HIGH8.8An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow ...
CVE-2019-9474HIGH7.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio...
CVE-2019-9473HIGH7.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio...
CVE-2019-2216HIGH7.3In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a...
CVE-2019-2089HIGH7.8In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could l...
CVE-2019-19611HIGH7.5An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to a...
CVE-2019-14309HIGH7.5Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer...
CVE-2019-14303HIGH7.5Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD se...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now