2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-3692HIGH7.8The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate ...
CVE-2019-19898HIGH7.5In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the ...
CVE-2019-19895HIGH7.8In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system...
CVE-2019-19893HIGH7.5In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated...
CVE-2019-16514HIGH7.2An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remo...
CVE-2019-16513HIGH8.8An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to se...
CVE-2019-15712HIGH7.2An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow admi...
CVE-2019-14888HIGH7.5A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker...
CVE-2019-3691HIGH7.8A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE...
CVE-2019-17202HIGH7.8FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el...
CVE-2019-17201HIGH7.8FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el...
CVE-2019-18898HIGH7.8UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; ope...
CVE-2019-19835HIGH7.5SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of serv...
CVE-2019-20397HIGH8.8A double-free is present in libyang before v1.0-r1 in the function yyparse() when an organization field is not terminate...
CVE-2019-20394HIGH8.8A double-free is present in libyang before v1.0-r3 in the function yyparse() when a type statement in used in a notifica...
CVE-2019-20393HIGH8.8A double-free is present in libyang before v1.0-r1 in the function yyparse() when an empty description is used. Applicat...
CVE-2019-19834HIGH7.2Directory Traversal in ruckus_cli2 in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote attacker to jail...
CVE-2019-16792HIGH7.5Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would heade...
CVE-2019-5647HIGH7.1The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after ...
CVE-2019-6858HIGH7.8A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1)...
CVE-2019-20388HIGH7.5xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
CVE-2019-20387HIGH7.5repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose lengt...
CVE-2019-19414HIGH7.5There is an integer overflow vulnerability in LDAP server of some Huawei products. Due to insufficient input validation,...
CVE-2019-19413HIGH7.5There is an integer overflow vulnerability in LDAP client of some Huawei products. Due to insufficient input validation,...
CVE-2019-19886HIGH7.5Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in lar...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now