2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16651MEDIUM5.3An issue was discovered on Virgin Media Super Hub 3 (based on ARRIS TG2492) devices. Because their SNMP commands have in...
CVE-2019-9060HIGH7.5An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExte...
CVE-2019-10941MEDIUM5.3A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality ...
CVE-2019-20101MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view whitelist rules via ...
CVE-2019-5318MEDIUM6.5A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba Operating System Software version(s): 6...
CVE-2019-10095CRITICAL9.8bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpre...
CVE-2019-25052CRITICAL9.1In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptogr...
CVE-2019-14453HIGH8.8An issue was discovered in Comelit "App lejos de casa (web)" 2.8.0. It allows privilege escalation via modified domus an...
CVE-2019-9983Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2019-20467CRITICAL9.8An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a...
CVE-2019-25051HIGH7.8objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::Strin...
CVE-2019-25050HIGH7.8netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_g...
CVE-2019-3752HIGH8.2Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (ID...
CVE-2019-11098MEDIUM6.8Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalatio...
CVE-2019-25049HIGH7.1LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx).
CVE-2019-25048HIGH7.1LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_...
CVE-2019-18906CRITICAL9.8A Improper Authentication vulnerability in cryptctl of SUSE Linux Enterprise Server for SAP 12-SP5, SUSE Manager Server ...
CVE-2019-25047MEDIUM6.1Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling i...
CVE-2019-7002Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2019-9475MEDIUM5.5In /proc/net of the kernel filesystem, there is a possible information leak due to a permissions bypass. This could lead...
CVE-2019-25046MEDIUM6.1The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
CVE-2019-17567MEDIUM5.3Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by ...
CVE-2019-25045HIGH7.8An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_s...
CVE-2019-14584HIGH7.8Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege...
CVE-2019-12067MEDIUM6.5The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now