2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-12765CRITICAL9.8An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection.
CVE-2019-10160CRITICAL9.8A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 af...
CVE-2019-3723CRITICAL9.1Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter t...
CVE-2019-7671CRITICAL9Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret...
CVE-2019-12739CRITICAL9lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution vi...
CVE-2019-10149CRITICAL9.8A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(...
CVE-2019-11356CRITICAL9.8The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execut...
CVE-2019-6742CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 pr...
CVE-2019-6741CRITICAL9.3This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 pr...
CVE-2019-11580CRITICAL9.8Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac...
CVE-2019-9874CRITICAL9.8Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an...
CVE-2019-8457CRITICAL9.8SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when hand...
CVE-2019-9670CRITICAL9.8mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX...
CVE-2019-6958CRITICAL9.1A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI...
CVE-2019-6957CRITICAL9.8A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI...
CVE-2019-12450CRITICAL9.8file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while ...
CVE-2019-12165CRITICAL9.8MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6....
CVE-2019-12288CRITICAL9.8An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devi...
CVE-2019-7096CRITICAL9.8Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after...
CVE-2019-7088CRITICAL9.8Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7107CRITICAL9.8Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation coul...
CVE-2019-11873CRITICAL9.8wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client ...
CVE-2019-6808CRITICAL9.8A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quant...
CVE-2019-6814CRITICAL9.8A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh...
CVE-2019-11634CRITICAL9.8Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now