2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-10970CRITICAL9.8In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v...
CVE-2019-7003CRITICAL10A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacke...
CVE-2019-12525CRITICAL9.8An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authen...
CVE-2019-11062CRITICAL9.8The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". T...
CVE-2019-13560CRITICAL9.8D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to force a blank password via the apply_sec.cgi se...
CVE-2019-12838CRITICAL9.8SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection.
CVE-2019-12803CRITICAL9.8In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file e...
CVE-2019-0330CRITICAL9.1The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), versi...
CVE-2019-13132CRITICAL9.8In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting t...
CVE-2019-13224CRITICAL9.8A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information d...
CVE-2019-13478CRITICAL9.8The Yoast SEO plugin before 11.6-RC5 for WordPress does not properly restrict unfiltered HTML in term descriptions.
CVE-2019-13413CRITICAL9.8The Rencontre plugin before 3.1.3 for WordPress allows SQL Injection via inc/rencontre_widget.php.
CVE-2019-13372CRITICAL9.8/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote atta...
CVE-2019-13144CRITICAL9.8myTinyTodo 1.3.3 through 1.4.3 allows CSV Injection. This is fixed in 1.5.
CVE-2019-7257CRITICAL10Linear eMerge E3-Series devices allow Unrestricted File Upload.
CVE-2019-7256CRITICAL9.8Linear eMerge E3-Series devices allow Command Injections.
CVE-2019-7261CRITICAL9.8Linear eMerge E3-Series devices have Hard-coded Credentials.
CVE-2019-7269CRITICAL9.8Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
CVE-2019-7268CRITICAL10Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
CVE-2019-7267CRITICAL9.8Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
CVE-2019-7266CRITICAL9.8Linear eMerge 50P/5000P devices allow Authentication Bypass.
CVE-2019-7265CRITICAL9.8Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
CVE-2019-4087CRITICAL9.8IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents are vulnerable to a stack-based buffer overflow, caused by i...
CVE-2019-7274CRITICAL9.8Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
CVE-2019-7667CRITICAL9.8Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable nam...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now