2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14463CRITICAL9.1An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_...
CVE-2019-14462CRITICAL9.1An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_...
CVE-2019-10185HIGH8.6It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extrac...
CVE-2019-10181HIGH8.1It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file wit...
CVE-2019-7000MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potenti...
CVE-2019-10198MEDIUM6.5An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were sear...
CVE-2019-10189MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in an assignment group could modify group overr...
CVE-2019-10188MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides fo...
CVE-2019-10187MEDIUM4.3A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Users with permission to delete entries from a glossary ...
CVE-2019-10186HIGH8.8A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML...
CVE-2019-10182HIGH8.2It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files....
CVE-2019-14459HIGH7.5nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c ...
CVE-2019-14456Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging....
CVE-2019-12797CRITICAL9.8A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus o...
CVE-2019-3960Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute a...
CVE-2019-3959Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tric...
CVE-2019-3958Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross...
CVE-2019-1901HIGH8.8A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Inf...
CVE-2019-12750Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition,...
CVE-2019-5060HIGH8.8An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially ...
CVE-2019-5059HIGH8.8An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-5058HIGH8.8An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-5057HIGH8.8An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-5020MEDIUM5.5An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially craf...
CVE-2019-4165HIGH7.5IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow a remote attacker to cause a denial of service attack using repeated r...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now