2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4385MEDIUM6.5IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can r...
CVE-2019-4384MEDIUM4.3IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send ...
CVE-2019-4364HIGH8IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to exe...
CVE-2019-4303MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-12814MEDIUM5.9A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enable...
CVE-2019-10257Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restr...
CVE-2019-12436Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is re...
CVE-2019-12435Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is ...
CVE-2019-3954Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi...
CVE-2019-3896HIGH7A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker...
CVE-2019-11479HIGH7.5Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fra...
CVE-2019-11478MEDIUM5.3Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be...
CVE-2019-11477HIGH7.5Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux ...
CVE-2019-11271HIGH7.8Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials w...
CVE-2019-11040CRITICAL9.1When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11039CRITICAL9.1Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may pe...
CVE-2019-11038MEDIUM5.3When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD exten...
CVE-2019-10085In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or e...
CVE-2019-3953Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi...
CVE-2019-12881HIGH7.8i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allow...
CVE-2019-12133Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDR...
CVE-2019-12592A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome all...
CVE-2019-12875Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --...
CVE-2019-12874An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through ...
CVE-2019-4142HIGH8.8IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attack...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now