2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6745Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12828. Reason: This candidate is a reservation d...
CVE-2019-12943HIGH8.1TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of s...
CVE-2019-12942MEDIUM6.5TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is una...
CVE-2019-11669HIGH7.5Modifiable read only check box In Micro Focus Service Manager, versions 9.60p1, 9.61, 9.62. This vulnerability could be ...
CVE-2019-11668HIGH7.5HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9...
CVE-2019-12996MEDIUM5.3In Mendix 7.23.5 and earlier, issue in XML import mappings allow DOCTYPE declarations in the XML input that is potential...
CVE-2019-10256CRITICAL9.8An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found.
CVE-2019-14457CRITICAL9.8VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header.
CVE-2019-11497HIGH7.5In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDC...
CVE-2019-11496CRITICAL9.1In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and writ...
CVE-2019-11495CRITICAL9.8In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server use...
CVE-2019-11467HIGH7.5In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index ...
CVE-2019-11466MEDIUM5.3In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that do...
CVE-2019-1563LOW3.7In situations where an attacker receives automated notification of the success or failure of a decryption attempt an att...
CVE-2019-1549MEDIUM5.3OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event...
CVE-2019-1547MEDIUM4.7Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. How...
CVE-2019-12105HIGH8.2In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer respo...
CVE-2019-11465MEDIUM5.3An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block comman...
CVE-2019-11464MEDIUM6.1Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-F...
CVE-2019-0365HIGH7.5SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versi...
CVE-2019-0364MEDIUM4.3Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1....
CVE-2019-0363HIGH7.1Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1....
CVE-2019-0361MEDIUM6.1SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) do...
CVE-2019-0357MEDIUM6.7The administrator of SAP HANA database, before versions 1.0 and 2.0, can misuse HANA to execute commands with operating ...
CVE-2019-0356MEDIUM4.3Under certain conditions SAP NetWeaver Process Integration Runtime Workbench – MESSAGING and SAP_XIAF (before versions 7...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now