2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-8352CRITICAL9.8By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen...
CVE-2019-4279CRITICAL9.8IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with ...
CVE-2019-10910CRITICAL9.8In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when servic...
CVE-2019-0708CRITICAL9.8A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau...
CVE-2019-3725CRITICAL9.8RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable ...
CVE-2019-6572CRITICAL9.1A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI ...
CVE-2019-3568CRITICAL9.8A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTC...
CVE-2019-10922CRITICAL9.8A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All ...
CVE-2019-10919CRITICAL9.4A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access t...
CVE-2019-1867CRITICAL10A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attack...
CVE-2019-6548CRITICAL9.8GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may all...
CVE-2019-11835CRITICAL9.8cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
CVE-2019-11834CRITICAL9.8cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
CVE-2019-11831CRITICAL9.8The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent...
CVE-2019-5021CRITICAL9.8Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne...
CVE-2019-11510CRITICAL10In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent...
CVE-2019-9505CRITICAL9.8The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters...
CVE-2019-11766CRITICAL9.8dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature.
CVE-2019-11036CRITICAL9.1When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3...
CVE-2019-1804CRITICAL9.8A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode ...
CVE-2019-11683CRITICAL9.8udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause...
CVE-2019-10952CRITICAL9.8An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code exec...
CVE-2019-11627CRITICAL9.8gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a Use...
CVE-2019-3939CRITICAL9.8Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator...
CVE-2019-3935CRITICAL9.1Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide sh...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now