2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13556HIGH8.8In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of prop...
CVE-2019-11664MEDIUM6.5Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,...
CVE-2019-11663MEDIUM6.5Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9...
CVE-2019-11662MEDIUM4.3Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9....
CVE-2019-11661HIGH8.3Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34...
CVE-2019-5534HIGH7.7VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc...
CVE-2019-5532HIGH7.7VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc...
CVE-2019-5067CRITICAL9.8An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object poi...
CVE-2019-5066CRITICAL9.8An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 fo...
CVE-2019-5042HIGH8.8An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19...
CVE-2019-15301CRITICAL9.8A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13...
CVE-2019-13552HIGH8.8In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validat...
CVE-2019-13550CRITICAL9.8In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensit...
CVE-2019-9680MEDIUM5.3Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of...
CVE-2019-9679HIGH8.8Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after...
CVE-2019-9678HIGH7.5Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crash...
CVE-2019-9677CRITICAL9.8The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer ov...
CVE-2019-14458HIGH7.5VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header.
CVE-2019-1975MEDIUM6.1A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker t...
CVE-2019-12620MEDIUM5.3A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote ...
CVE-2019-14254CRITICAL9.8An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are m...
CVE-2019-14253MEDIUM6.5An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and ...
CVE-2019-14252HIGH7.2An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, on...
CVE-2019-15843HIGH7.4A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition in...
CVE-2019-16399CRITICAL9.8Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now