2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-16410CRITICAL9.1An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble i...
CVE-2019-15699CRITICAL9.1An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the par...
CVE-2019-16383CRITICAL9.4MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a...
CVE-2019-16748CRITICAL9.8In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while han...
CVE-2019-16746CRITICAL9.8An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of va...
CVE-2019-16377CRITICAL9.8The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control.
CVE-2019-3416CRITICAL9.8All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp...
CVE-2019-16722CRITICAL9.8ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an s...
CVE-2019-16705CRITICAL9.1Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in lib...
CVE-2019-16702CRITICAL9.8Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa...
CVE-2019-16696CRITICAL9.8phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used.
CVE-2019-16695CRITICAL9.8phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used.
CVE-2019-16694CRITICAL9.8phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used...
CVE-2019-16693CRITICAL9.8phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used.
CVE-2019-16692CRITICAL9.8phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us...
CVE-2019-16656CRITICAL9.8joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of ...
CVE-2019-16650CRITICAL10On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has...
CVE-2019-16649CRITICAL10On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the v...
CVE-2019-6650CRITICAL9.1F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5...
CVE-2019-6649CRITICAL9.1F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 a...
CVE-2019-5521CRITICAL9.6VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x...
CVE-2019-16644CRITICAL9.8App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= s...
CVE-2019-16642CRITICAL9.8App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/gr...
CVE-2019-15088CRITICAL9.8An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under speci...
CVE-2019-14914CRITICAL9.1An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now