2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16162HIGH7.5Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c.
CVE-2019-16161HIGH7.5Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c.
CVE-2019-12405CRITICAL9.8Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in t...
CVE-2019-16159HIGH7.5BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon...
CVE-2019-12465HIGH8.1An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t...
CVE-2019-12464HIGH7.5An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /...
CVE-2019-12463HIGH8.8An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph...
CVE-2019-10671HIGH8.8An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queri...
CVE-2019-10670MEDIUM6.1An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for...
CVE-2019-16148MEDIUM6.1Sakai through 12.6 allows XSS via a chat user name.
CVE-2019-16146MEDIUM4.8Gophish through 0.8.0 allows XSS via a username.
CVE-2019-16114CRITICAL9.8In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted databas...
CVE-2019-15895HIGH7.5search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
CVE-2019-15639HIGH7.5main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a ...
CVE-2019-10669HIGH7.2An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev...
CVE-2019-10668CRITICAL9.1An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not en...
CVE-2019-10667MEDIUM5.3An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exac...
CVE-2019-10666HIGH8.1An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the includ...
CVE-2019-10665CRITICAL9.8An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/com...
CVE-2019-16144HIGH7.5An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and ...
CVE-2019-16143CRITICAL9.8An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HM...
CVE-2019-16142CRITICAL9.8An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable re...
CVE-2019-16141HIGH7.5An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy.
CVE-2019-16140CRITICAL9.8An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion.
CVE-2019-16139CRITICAL9.8An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now