2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25046MEDIUM6.1The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.
CVE-2019-17567MEDIUM5.3Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by ...
CVE-2019-25045HIGH7.8An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_s...
CVE-2019-14584HIGH7.8Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege...
CVE-2019-12067MEDIUM6.5The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when...
CVE-2019-4730HIGH7.1IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da...
CVE-2019-4724HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...
CVE-2019-4723HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...
CVE-2019-4722MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t...
CVE-2019-4653MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4471MEDIUM6.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2019-25030MEDIUM5.5In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke...
CVE-2019-25029CRITICAL9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o...
CVE-2019-4588HIGH7.8IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2019-14836HIGH8.8A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An at...
CVE-2019-12348CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
CVE-2019-14827MEDIUM6.1A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren...
CVE-2019-25044HIGH7.8The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the...
CVE-2019-10062MEDIUM6.1The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera...
CVE-2019-19276MEDIUM5.3A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <...
CVE-2019-25043MEDIUM5.3ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a...
CVE-2019-25042CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that t...
CVE-2019-25041HIGH7.5Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that...
CVE-2019-25040HIGH7.5Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that thi...
CVE-2019-25039CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now