2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-20406HIGH7.8The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0...
CVE-2019-20400HIGH7.8The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directo...
CVE-2019-20104HIGH7.5The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote...
CVE-2019-12180HIGH7.8An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th...
CVE-2019-11516HIGH8.1An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Ex...
CVE-2019-4613HIGH8.8IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...
CVE-2019-16204HIGH7.5Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets ...
CVE-2019-16203HIGH7.5Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these ...
CVE-2019-12528HIGH7.5An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive informat...
CVE-2019-15613HIGH8A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking...
CVE-2019-4541HIGH7.2IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass a...
CVE-2019-4540HIGH7.5IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to d...
CVE-2019-19273HIGH7.8On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL...
CVE-2019-9674HIGH7.5Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a...
CVE-2019-9502HIGH8.8The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is la...
CVE-2019-9501HIGH8.8The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a da...
CVE-2019-16893HIGH7.5The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the...
CVE-2019-18193HIGH7.5In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain co...
CVE-2019-13000HIGH7.5Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states...
CVE-2019-12999HIGH7.5Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
CVE-2019-12998HIGH7.5c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md ...
CVE-2019-4720HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia...
CVE-2019-19550HIGH7.5Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of a...
CVE-2019-20358HIGH7.8Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to...
CVE-2019-18634HIGH7.8In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now