2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-15000CRITICAL9.8The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6...
CVE-2019-3689CRITICAL9.8The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux En...
CVE-2019-3758CRITICAL9.8RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allo...
CVE-2019-11211CRITICAL9.9The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analyt...
CVE-2019-11210CRITICAL10The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analyt...
CVE-2019-13558CRITICAL9.8In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of ...
CVE-2019-5067CRITICAL9.8An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object poi...
CVE-2019-5066CRITICAL9.8An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 fo...
CVE-2019-15301CRITICAL9.8A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13...
CVE-2019-13550CRITICAL9.8In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensit...
CVE-2019-9677CRITICAL9.8The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer ov...
CVE-2019-14254CRITICAL9.8An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are m...
CVE-2019-16399CRITICAL9.8Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce...
CVE-2019-16199CRITICAL9.8eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with...
CVE-2019-6840CRITICAL9.8A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.m...
CVE-2019-6837CRITICAL9.1A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX serve...
CVE-2019-16378CRITICAL9.8OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: a...
CVE-2019-16239CRITICAL9.8process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encodin...
CVE-2019-15131CRITICAL9.8In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allo...
CVE-2019-5482CRITICAL9.8Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.
CVE-2019-5481CRITICAL9.8Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
CVE-2019-15741CRITICAL9.8An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a pri...
CVE-2019-10071CRITICAL9.8The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side chan...
CVE-2019-16366CRITICAL9.8In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from f...
CVE-2019-0195CRITICAL9.8Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it do...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now