2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12834HIGH7.3In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the websi...
CVE-2019-10191HIGH7.5A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to do...
CVE-2019-10190HIGH7.5A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allow...
CVE-2019-13618In GPAC before 0.8.0, isomedia/isom_read.c in libgpac.a has a heap-based buffer over-read, as demonstrated by a crash in...
CVE-2019-13617njs through 0.3.3, used in NGINX, has a heap-based buffer over-read in nxt_vsprintf in nxt/nxt_sprintf.c during error ha...
CVE-2019-13616HIGH8.1SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in vid...
CVE-2019-13615libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buf...
CVE-2019-13605In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in ...
CVE-2019-13603MEDIUM5.9An issue was discovered in the HID Global DigitalPersona (formerly Crossmatch) U.are.U 4500 Fingerprint Reader Windows B...
CVE-2019-13383MEDIUM5.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern...
CVE-2019-13360In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login pro...
CVE-2019-1576HIGH8.8Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PA...
CVE-2019-1575HIGH8.8Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS ...
CVE-2019-1010292Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corrupti...
CVE-2019-1010290Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is sup...
CVE-2019-1010048Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-1010043Quake3e < 5ed740d is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The com...
CVE-2019-13612MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and li...
CVE-2019-1010062PluckCMS 4.7.4 and earlier is affected by: CWE-434 Unrestricted Upload of File with Dangerous Type. The impact is: get w...
CVE-2019-1010061Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10364. Reason: This candidate is a reservation d...
CVE-2019-1010060NASA CFITSIO prior to 3.43 is affected by: Buffer Overflow. The impact is: arbitrary code execution. The component is: o...
CVE-2019-1010057HIGH7.8nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of servic...
CVE-2019-1010018Zammad GmbH Zammad 2.3.0 and earlier is affected by: Cross Site Scripting (XSS) - CWE-80. The impact is: Execute java sc...
CVE-2019-13611An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerabilit...
CVE-2019-0234MEDIUM6.1A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did no...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now