2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10088A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. U...
CVE-2019-10961HIGH8.8In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper va...
CVE-2019-9141CRITICAL9.8ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers ...
CVE-2019-5501Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthentica...
CVE-2019-5493Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information ...
CVE-2019-14532CRITICAL9.8An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/has...
CVE-2019-14531An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Us...
CVE-2019-14235An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain ...
CVE-2019-14233An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behavio...
CVE-2019-14232HIGH7.5An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.te...
CVE-2019-10176MEDIUM4.2A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster ...
CVE-2019-4275MEDIUM5.5IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique cata...
CVE-2019-14529CRITICAL9.8OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CVE-2019-14528GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code.
CVE-2019-10938CRITICAL9.8A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 dev...
CVE-2019-10171HIGH7.5It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied i...
CVE-2019-10168HIGH7.8The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x b...
CVE-2019-10167HIGH7.8The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emul...
CVE-2019-10166HIGH7.8It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to u...
CVE-2019-14524HIGH7.8An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of ...
CVE-2019-14523HIGH7.8An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_lo...
CVE-2019-14517pandao Editor.md 1.5.0 allows XSS via the Javas&#99;ript: string.
CVE-2019-5401A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss ...
CVE-2019-14513HIGH7.5Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that ...
CVE-2019-14260On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injectio...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now