2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-15748CRITICAL9.8SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affe...
CVE-2019-15746CRITICAL9.8SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the ...
CVE-2019-17269CRITICAL9.8Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Pi...
CVE-2019-17267CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.h...
CVE-2019-17266CRITICAL9.8libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup...
CVE-2019-17240CRITICAL9.8bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many...
CVE-2019-17218CRITICAL9.1An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the commu...
CVE-2019-17216CRITICAL9.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authenticati...
CVE-2019-17215CRITICAL9.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforc...
CVE-2019-17206CRITICAL9.8Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3....
CVE-2019-17197CRITICAL9.8OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that ...
CVE-2019-17192CRITICAL9.8The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing ...
CVE-2019-17184CRITICAL9.8Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.226...
CVE-2019-16891CRITICAL9.8Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CVE-2019-17133CRITICAL9.8In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE,...
CVE-2019-17132CRITICAL9.8vBulletin through 5.5.4 mishandles custom avatars.
CVE-2019-17113CRITICAL9.8In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug....
CVE-2019-13957CRITICAL9.8In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the n...
CVE-2019-12736CRITICAL9.8JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, lead...
CVE-2019-12630CRITICAL9.8A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo...
CVE-2019-12157CRITICAL9.8In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands.
CVE-2019-11929CRITICAL9.8Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, ...
CVE-2019-10212CRITICAL9.8A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attack...
CVE-2019-13658CRITICAL9.8CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to exec...
CVE-2019-13025CRITICAL9.8Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Valida...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now