2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4730HIGH7.1IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da...
CVE-2019-4724HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...
CVE-2019-4723HIGH7.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre...
CVE-2019-4722MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t...
CVE-2019-4653MEDIUM5.4IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit...
CVE-2019-4471MEDIUM6.5IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2019-25030MEDIUM5.5In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke...
CVE-2019-25029CRITICAL9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o...
CVE-2019-4588HIGH7.8IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2019-14836HIGH8.8A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An at...
CVE-2019-12348CRITICAL9.8An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter.
CVE-2019-14827MEDIUM6.1A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren...
CVE-2019-25044HIGH7.8The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the...
CVE-2019-10062MEDIUM6.1The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera...
CVE-2019-19276MEDIUM5.3A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <...
CVE-2019-25043MEDIUM5.3ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a...
CVE-2019-25042CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that t...
CVE-2019-25041HIGH7.5Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that...
CVE-2019-25040HIGH7.5Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that thi...
CVE-2019-25039CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that...
CVE-2019-25038CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes ...
CVE-2019-25037HIGH7.5Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: Th...
CVE-2019-25036HIGH7.5Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that th...
CVE-2019-25035CRITICAL9.8Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vul...
CVE-2019-25034CRITICAL9.8Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. N...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now