2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-12941CRITICAL9.8AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary at...
CVE-2019-16278CRITICAL9.8Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co...
CVE-2019-17580CRITICAL9.8tonyy dormsystem through 1.3 allows SQL Injection in admin.php.
CVE-2019-17574CRITICAL9.1An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially...
CVE-2019-17553CRITICAL9.8An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17552CRITICAL9.8An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in...
CVE-2019-17408CRITICAL9.8parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because t...
CVE-2019-17545CRITICAL9.8GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exce...
CVE-2019-17544CRITICAL9.1libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp vi...
CVE-2019-17542CRITICAL9.8FFmpeg before 4.2 has a heap-based buffer overflow in vqa_decode_chunk because of an out-of-array access in vqa_decode_i...
CVE-2019-17539CRITICAL9.8In FFmpeg before 4.2, avcodec_open2 in libavcodec/utils.c allows a NULL pointer dereference and possibly unspecified oth...
CVE-2019-17531CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is ena...
CVE-2019-17510CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveragin...
CVE-2019-17509CRITICAL9.8D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveragin...
CVE-2019-17508CRITICAL9.8On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SER...
CVE-2019-17506CRITICAL9.8There are some web interfaces without authentication requirements on D-Link DIR-868L B1-2.03 and DIR-817LW A1-1.04 route...
CVE-2019-17059CRITICAL9.8A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remo...
CVE-2019-17495CRITICAL9.8A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative...
CVE-2019-9533CRITICAL9.8The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This co...
CVE-2019-9531CRITICAL9.8The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454...
CVE-2019-11526CRITICAL9.8An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable t...
CVE-2019-17455CRITICAL9.8Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthRespon...
CVE-2019-17320CRITICAL9.8NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary ch...
CVE-2019-1372CRITICAL10An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length o...
CVE-2019-1365CRITICAL9.9An elevation of privilege vulnerability exists when Microsoft IIS Server fails to check the length of a buffer prior to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now