2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13514HIGH7.8In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may tr...
CVE-2019-13513HIGH7.8In Delta Industrial Automation DOPSoft, Version 4.00.06.15 and prior, processing a specially crafted project file may tr...
CVE-2019-13512LOW3.3Fuji Electric FRENIC Loader 3.5.0.0 and prior is vulnerable to an out-of-bounds read vulnerability, which may allow an a...
CVE-2019-13511LOW3.3Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A m...
CVE-2019-13510Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciou...
CVE-2019-12809HIGH8.8Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that could allow remote attacke...
CVE-2019-9012HIGH7.5An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory a...
CVE-2019-9010CRITICAL9.8An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of ...
CVE-2019-9013HIGH8.8An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which res...
CVE-2019-14422An issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel w...
CVE-2019-13377MEDIUM5.9The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel atta...
CVE-2019-13223MEDIUM5.5A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a deni...
CVE-2019-13222HIGH7.1An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker t...
CVE-2019-13221HIGH7.8A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a...
CVE-2019-13220HIGH7.1Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker t...
CVE-2019-13219MEDIUM5.5A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a den...
CVE-2019-13218MEDIUM5.5Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of ...
CVE-2019-13217HIGH7.8A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a deni...
CVE-2019-12854HIGH7.5Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with m...
CVE-2019-11187Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account...
CVE-2019-10140MEDIUM5.5A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local ac...
CVE-2019-14789The Custom 404 Pro plugin 3.2.8 for WordPress has XSS via the wp-admin/admin.php?page=c4p-main page parameter.
CVE-2019-14788HIGH8.8wp-admin/admin-ajax.php?action=newsletters_exportmultiple in the Tribulant Newsletters plugin before 4.6.19 for WordPres...
CVE-2019-14786MEDIUM6.5The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.p...
CVE-2019-14784The "CP Contact Form with PayPal" plugin before 1.2.98 for WordPress has XSS in CSS edition.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now