2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-16125CRITICAL9.8In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injec...
CVE-2019-16124CRITICAL9.8In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to ...
CVE-2019-16119CRITICAL9.8SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control...
CVE-2019-16093CRITICAL9.8Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
CVE-2019-16092CRITICAL9.8Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.
CVE-2019-10891CRITICAL9.8An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls syste...
CVE-2019-9855CRITICAL9.8LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra...
CVE-2019-13656CRITICAL9.8An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11....
CVE-2019-14813CRITICAL9.8A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly se...
CVE-2019-15954CRITICAL9.9An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote...
CVE-2019-1976CRITICAL9.8A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could a...
CVE-2019-15926CRITICAL9.1An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstrea...
CVE-2019-6644CRITICAL9.4Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1...
CVE-2019-5608CRITICAL9.8In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE bef...
CVE-2019-15780CRITICAL9.8The formidable plugin before 4.02.01 for WordPress has unsafe deserialization.
CVE-2019-11064CRITICAL9.8A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker ca...
CVE-2019-11063CRITICAL10A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22)...
CVE-2019-11061CRITICAL10A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area...
CVE-2019-12643CRITICAL10A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated...
CVE-2019-4169CRITICAL9.1IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC...
CVE-2019-14300CRITICAL9.8Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a de...
CVE-2019-14308CRITICAL9.8Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of ...
CVE-2019-15562CRITICAL9.8GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input ...
CVE-2019-6695CRITICAL9.8Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may...
CVE-2019-6698CRITICAL9.8Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now