2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-20213HIGH7.5D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v...
CVE-2019-20205HIGH8.8libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
CVE-2019-18568HIGH8.8Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a...
CVE-2019-20197HIGH8.8In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id pa...
CVE-2019-9668HIGH7.5An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote...
CVE-2019-9197HIGH8.8The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
CVE-2019-7751HIGH7.5A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, for...
CVE-2019-20176HIGH7.5In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CVE-2019-10229HIGH8.8An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the dire...
CVE-2019-20175HIGH7.5An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEM...
CVE-2019-20172HIGH7.8Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only ...
CVE-2019-7479HIGH7.2A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne...
CVE-2019-19032HIGH8.1XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an ...
CVE-2019-19031HIGH8.1Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS...
CVE-2019-16790HIGH8.8In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only auth...
CVE-2019-20149HIGH7.5ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflic...
CVE-2019-19470HIGH7.8Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM...
CVE-2019-13465HIGH8.6An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3...
CVE-2019-20140HIGH8.8An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif...
CVE-2019-19739HIGH7.5MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent ...
CVE-2019-19737HIGH8.8MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sen...
CVE-2019-19734HIGH8.8_account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter in...
CVE-2019-19732HIGH7.2translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly inser...
CVE-2019-17558HIGH7.5Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V...
CVE-2019-20138HIGH7.5The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for li...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now