2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-1913CRITICAL9.8Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow a...
CVE-2019-1912CRITICAL9.1A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe...
CVE-2019-14697CRITICAL9.8musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In s...
CVE-2019-14695CRITICAL9.8A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat...
CVE-2019-9141CRITICAL9.8ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers ...
CVE-2019-14532CRITICAL9.8An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/has...
CVE-2019-14529CRITICAL9.8OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.
CVE-2019-10938CRITICAL9.8A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 dev...
CVE-2019-14495CRITICAL9.8webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.
CVE-2019-13572CRITICAL9.8The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection.
CVE-2019-14463CRITICAL9.1An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_...
CVE-2019-14462CRITICAL9.1An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_...
CVE-2019-12797CRITICAL9.8A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus o...
CVE-2019-5454CRITICAL9.8SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query i...
CVE-2019-14313CRITICAL9.8A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat...
CVE-2019-14431CRITICAL9.8In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based...
CVE-2019-14271CRITICAL9.8In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitc...
CVE-2019-13571CRITICAL9.8A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu...
CVE-2019-14379CRITICAL9.8SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (becau...
CVE-2019-13990CRITICAL9.8initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attack...
CVE-2019-14277CRITICAL9.8Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticat...
CVE-2019-5604CRITICAL9.6In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE bef...
CVE-2019-10744CRITICAL9.1Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked ...
CVE-2019-9885CRITICAL9.8eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php Studen...
CVE-2019-9884CRITICAL9.8eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password vali...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now