2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11678The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injec...
CVE-2019-11677The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML E...
CVE-2019-11676The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS at...
CVE-2019-11675The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let...
CVE-2019-0227HIGH7.5A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2...
CVE-2019-10952CRITICAL9.8An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code exec...
CVE-2019-6562MEDIUM5.4In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input...
CVE-2019-10954HIGH7.5An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major n...
CVE-2019-11641Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal va...
CVE-2019-11640An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_sim...
CVE-2019-11639An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum ...
CVE-2019-11638An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p ...
CVE-2019-11637An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at r...
CVE-2019-3791Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-11636Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from...
CVE-2019-4258MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerabili...
CVE-2019-11633HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylm...
CVE-2019-11632In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUn...
CVE-2019-11631Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-11628HIGH8.2An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 1...
CVE-2019-11627CRITICAL9.8gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a Use...
CVE-2019-0214In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the...
CVE-2019-0213In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. ...
CVE-2019-0194Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsup...
CVE-2019-3939CRITICAL9.8Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now