2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15919LOW3.3An issue was discovered in the Linux kernel before 5.0.10. SMB2_write in fs/cifs/smb2pdu.c has a use-after-free.
CVE-2019-15918HIGH7.8An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read...
CVE-2019-15917HIGH7An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() f...
CVE-2019-6646On BIG-IP 11.5.2-11.6.4 and Enterprise Manager 3.1.1, REST users with guest privileges may be able to escalate their pri...
CVE-2019-6643HIGH7.5On versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, and 11.5.2-11.6.4, an attacker sending spe...
CVE-2019-6647MEDIUM5.3On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authenticatio...
CVE-2019-6644CRITICAL9.4Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1...
CVE-2019-6648MEDIUM4.4On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k...
CVE-2019-6645HIGH7.5On BIG-IP 14.0.0-14.1.0.5, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, FTP traffic passing through a Virtual Server w...
CVE-2019-13976eGain Chat 15.0.3 allows unrestricted file upload.
CVE-2019-13975eGain Chat 15.0.3 allows HTML Injection.
CVE-2019-15916HIGH7.5An issue was discovered in the Linux kernel before 5.0.1. There is a memory leak in register_queue_kobjects() in net/cor...
CVE-2019-13522HIGH7.8An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of th...
CVE-2019-13518An attacker could use a specially crafted project file to overflow the buffer and execute code under the privileges of t...
CVE-2019-15814Multiple stored XSS vulnerabilities in Sentrifugo 3.2 could allow authenticated users to inject arbitrary web script or ...
CVE-2019-15813HIGH8.8Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb...
CVE-2019-13209Rancher 2 through 2.2.4 is vulnerable to a Cross-Site Websocket Hijacking attack that allows an exploiter to gain access...
CVE-2019-10988LOW3.4In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000,...
CVE-2019-15718MEDIUM4.4In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect...
CVE-2019-12588MEDIUM6.5The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the ...
CVE-2019-12587The EAP peer implementation in Espressif ESP-IDF 2.0.0 through 4.0.0 and ESP8266_NONOS_SDK 2.2.0 through 3.1.0 allows th...
CVE-2019-10709AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic...
CVE-2019-15903HIGH7.5In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too...
CVE-2019-15902MEDIUM5.6A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.1...
CVE-2019-15898Nagios Log Server before 2.0.8 allows Reflected XSS via the username on the Login page.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now