2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-25003HIGH7.5An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-cha...
CVE-2019-25002CRITICAL9.8An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itsel...
CVE-2019-25001HIGH7.5An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio...
CVE-2019-7726CRITICAL9.8modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP r...
CVE-2019-7725CRITICAL9.8includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies...
CVE-2019-20808MEDIUM6.5In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() ...
CVE-2019-16747HIGH7.5In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and ...
CVE-2019-16281HIGH7.5Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code ...
CVE-2019-15523MEDIUM5.3An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_...
CVE-2019-15080HIGH7.5An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo...
CVE-2019-15079HIGH7.5A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This ...
CVE-2019-15078HIGH7.5An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The ...
CVE-2019-12953MEDIUM5.3Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a differe...
CVE-2019-12768CRITICAL9.8An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass au...
CVE-2019-11786MEDIUM4.3Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authentic...
CVE-2019-11785MEDIUM4.3Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earli...
CVE-2019-11784MEDIUM6.5Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e...
CVE-2019-11783MEDIUM6.5Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 an...
CVE-2019-11782MEDIUM6.5Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authentic...
CVE-2019-11781HIGH8.8Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, a...
CVE-2019-16959MEDIUM6.5SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
CVE-2019-16957MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
CVE-2019-16955MEDIUM5.4SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
CVE-2019-14481MEDIUM5.4AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successfu...
CVE-2019-14479HIGH8.8AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can exe...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now