2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1968HIGH7.5A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a...
CVE-2019-1967HIGH7.5A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remot...
CVE-2019-1966HIGH7.8A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Intercon...
CVE-2019-13526Datalogic AV7000 Linear barcode scanner all versions prior to 4.6.0.0 is vulnerable to authentication bypass, which may ...
CVE-2019-12754Symantec My VIP portal, previous version which has already been auto updated, was susceptible to a cross-site scripting ...
CVE-2019-12753An information disclosure vulnerability in Symantec Reporter web UI 10.3 prior to 10.3.2.5 allows a malicious authentica...
CVE-2019-12402HIGH7.5The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop w...
CVE-2019-11658Information exposure in Micro Focus Content Manager, versions 9.1, 9.2 and 9.3. This vulnerability when configured to us...
CVE-2019-8461Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH lo...
CVE-2019-11364An OS Command Injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to inject arbi...
CVE-2019-11363A SQL injection vulnerability in Snare Central before 7.4.5 allows remote authenticated attackers to execute arbitrary S...
CVE-2019-11396An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (fil...
CVE-2019-15811In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
CVE-2019-14979cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.17 for WordPress allows Parameter...
CVE-2019-14978/payu/icpcheckout/ in the WooCommerce PayU India Payment Gateway plugin 2.1.1 for WordPress allows Parameter Tampering i...
CVE-2019-14977Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-14970A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-ba...
CVE-2019-14778The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-...
CVE-2019-14777The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
CVE-2019-14776A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafte...
CVE-2019-14534In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c...
CVE-2019-14533The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
CVE-2019-13608HIGH7.5Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE at...
CVE-2019-15807MEDIUM4.7In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discov...
CVE-2019-15806CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now