2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11654HIGH7.5Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerab...
CVE-2019-15531MEDIUM6.5GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/d...
CVE-2019-15530An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo...
CVE-2019-15529An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo...
CVE-2019-15528An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo...
CVE-2019-15527An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo...
CVE-2019-15526An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo...
CVE-2019-13014MEDIUM5.5Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have m...
CVE-2019-13013MEDIUM5.5Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. T...
CVE-2019-10751All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to wri...
CVE-2019-10750CRITICAL9.8deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into add...
CVE-2019-10747CRITICAL9.8set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked in...
CVE-2019-10746CRITICAL9.8mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep coul...
CVE-2019-15525There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1.
CVE-2019-15520comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
CVE-2019-15519Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
CVE-2019-15518Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
CVE-2019-15517jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
CVE-2019-15516Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply remove...
CVE-2019-8447The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export file...
CVE-2019-8446MEDIUM5.3The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via...
CVE-2019-8445MEDIUM5.3Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a...
CVE-2019-8444MEDIUM5.4The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta...
CVE-2019-14999The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before vers...
CVE-2019-13423HIGH8.8Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user co...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now