2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5497NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default acc...
CVE-2019-10979SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account pass...
CVE-2019-7278Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service.
CVE-2019-7277Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure.
CVE-2019-7276Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
CVE-2019-7275MEDIUM6.1Optergy Proton/Enterprise devices allow Open Redirect.
CVE-2019-3962Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit t...
CVE-2019-13137MEDIUM6.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c.
CVE-2019-13136ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c.
CVE-2019-13135HIGH8.8ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut....
CVE-2019-13134MEDIUM5.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c.
CVE-2019-13133MEDIUM5.5ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c.
CVE-2019-7670HIGH7.2Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo...
CVE-2019-7669HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allo...
CVE-2019-7668Prima Systems FlexAir devices have Default Credentials.
CVE-2019-7667CRITICAL9.8Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable nam...
CVE-2019-7666HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu...
CVE-2019-7281HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may a...
CVE-2019-7280HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by br...
CVE-2019-7279Optergy Proton/Enterprise devices have Hard-coded Credentials.
CVE-2019-1578Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker...
CVE-2019-1577Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject...
CVE-2019-13024Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra...
CVE-2019-12826A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 ...
CVE-2019-13131Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitr...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now