2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-4336CRITICAL9.8IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a...
CVE-2019-13107CRITICAL9.8Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c
CVE-2019-11829CRITICAL9.8OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote ...
CVE-2019-11821CRITICAL9.8SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 ...
CVE-2019-10993CRITICAL9.8In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote a...
CVE-2019-10991CRITICAL9.8In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack ...
CVE-2019-10989CRITICAL9.8In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of...
CVE-2019-10985CRITICAL9.1In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of...
CVE-2019-1620CRITICAL9.8A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2019-1619CRITICAL9.8A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2019-6168CRITICAL9.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2019-6167CRITICAL9.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution.
CVE-2019-1848CRITICAL9.3A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to ...
CVE-2019-2729CRITICAL9.8Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte...
CVE-2019-12900CRITICAL9.8BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.
CVE-2019-11040CRITICAL9.1When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7...
CVE-2019-11039CRITICAL9.1Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may pe...
CVE-2019-5016CRITICAL9.1An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadyS...
CVE-2019-6327CRITICAL9.8HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s...
CVE-2019-10126CRITICAL9.8A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net...
CVE-2019-11119CRITICAL9.8Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticat...
CVE-2019-6580CRITICAL9.8A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All ver...
CVE-2019-3888CRITICAL9.8A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials throug...
CVE-2019-3412CRITICAL9.8All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfa...
CVE-2019-3409CRITICAL9All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerab...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now