2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11839njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to nj...
CVE-2019-11838njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to ...
CVE-2019-11837njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related t...
CVE-2019-11353The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in p...
CVE-2019-11323MEDIUM5.9HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, H...
CVE-2019-0226Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directo...
CVE-2019-11836The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persi...
CVE-2019-11820MEDIUM5.5Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users...
CVE-2019-11835CRITICAL9.8cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CVE-2019-11834CRITICAL9.8cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
CVE-2019-11832TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the app...
CVE-2019-11831CRITICAL9.8The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent...
CVE-2019-11830PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1...
CVE-2019-7442An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault...
CVE-2019-9698Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulne...
CVE-2019-8285Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentiall...
CVE-2019-11494HIGH7.5In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects pr...
CVE-2019-11458An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can ...
CVE-2019-11406Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.
CVE-2019-11398Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra...
CVE-2019-5021CRITICAL9.8Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne...
CVE-2019-5014MEDIUM6.5An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks...
CVE-2019-2054HIGH7.8In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies th...
CVE-2019-2053In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This...
CVE-2019-2052In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote inf...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now