2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1010263Perl Crypt::JWT prior to 0.023 is affected by: Incorrect Access Control. The impact is: allow attackers to bypass authen...
CVE-2019-13619HIGH7.5In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could c...
CVE-2019-13577SnmpAdm.exe in MAPLE WBT SNMP Administrator v2.0.195.15 has an Unauthenticated Remote Buffer Overflow via a long string ...
CVE-2019-13493In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u...
CVE-2019-13448An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ...
CVE-2019-13447An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ...
CVE-2019-12876Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, l...
CVE-2019-11535Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) al...
CVE-2019-13631In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device ...
CVE-2019-13585CRITICAL9.8The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP reque...
CVE-2019-13584The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP ...
CVE-2019-13614CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and e...
CVE-2019-13613CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180...
CVE-2019-13403Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leadi...
CVE-2019-13346In MyT 1.5.1, the User[username] parameter has XSS.
CVE-2019-12475In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
CVE-2019-12175In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka K...
CVE-2019-1010091MEDIUM6.1tinymce 4.7.11, 4.7.12 is affected by: CWE-79: Improper Neutralization of Input During Web Page Generation. The impact i...
CVE-2019-13626MEDIUM6.5SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an...
CVE-2019-13573CRITICAL9.8A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres...
CVE-2019-10354MEDIUM4.3A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attacker...
CVE-2019-10353CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obt...
CVE-2019-10352A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/...
CVE-2019-13453Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a ...
CVE-2019-4430HIGH7.5IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now