2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5433A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted ad...
CVE-2019-5432HIGH7.5A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0...
CVE-2019-5431MEDIUM5.4This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulner...
CVE-2019-5430In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes...
CVE-2019-3799MEDIUM6.5Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, an...
CVE-2019-3797LOW3.5This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the...
CVE-2019-3565HIGH7.5Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers o...
CVE-2019-3564HIGH7.5Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a resul...
CVE-2019-3559HIGH7.5Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a res...
CVE-2019-3558HIGH7.5Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a r...
CVE-2019-3552HIGH7.5C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown ty...
CVE-2019-10249HIGH8.1All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artif...
CVE-2019-11767Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the ...
CVE-2019-11766CRITICAL9.8dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
CVE-2019-6619HIGH7.5On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when...
CVE-2019-6618On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource A...
CVE-2019-6617MEDIUM6.5On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource ...
CVE-2019-6616HIGH7.2On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with...
CVE-2019-6615MEDIUM4.9On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Administrator and Resourc...
CVE-2019-6614MEDIUM6.5On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrite...
CVE-2019-6158HIGH8.7An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being writt...
CVE-2019-3894HIGH8.8It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a Securi...
CVE-2019-3805MEDIUM4.7A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d...
CVE-2019-3400MEDIUM6.1The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to ...
CVE-2019-11037MEDIUM4.9In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now