2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13638GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch fil...
CVE-2019-13565HIGH7.5An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relyin...
CVE-2019-13387MEDIUM6.1In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir...
CVE-2019-13386HIGH8.8In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attack...
CVE-2019-13385MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allo...
CVE-2019-13382UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA...
CVE-2019-13057MEDIUM4.9An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (databas...
CVE-2019-14282The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a...
CVE-2019-14281The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third ...
CVE-2019-14280In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe...
CVE-2019-14277CRITICAL9.8Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticat...
CVE-2019-14275MEDIUM5.5Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
CVE-2019-14274MEDIUM5.5MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
CVE-2019-5607HIGH7.8In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE bef...
CVE-2019-5606HIGH7.8In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE bef...
CVE-2019-5605MEDIUM6.5In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, du...
CVE-2019-5604CRITICAL9.6In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE bef...
CVE-2019-5603HIGH7.8In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE bef...
CVE-2019-10976Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the ...
CVE-2019-10974MEDIUM5.5NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from ...
CVE-2019-10972MEDIUM5.5Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker prov...
CVE-2019-10744CRITICAL9.1Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked ...
CVE-2019-1010147Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. Th...
CVE-2019-0202The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In ...
CVE-2019-11922A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to wr...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now