2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11218Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server...
CVE-2019-11217The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the conte...
CVE-2019-10008Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session...
CVE-2019-9951Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M...
CVE-2019-9950Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M...
CVE-2019-9635NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.
CVE-2019-10691The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting...
CVE-2019-3882MEDIUM5.5A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory ...
CVE-2019-3868LOW3.8Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for bro...
CVE-2019-3793CRITICAL9.8Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x p...
CVE-2019-3789MEDIUM6.5Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to ro...
CVE-2019-3786HIGH7.1Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup script...
CVE-2019-9928GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a ser...
CVE-2019-9734Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of c...
CVE-2019-7214SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co...
CVE-2019-7213SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary...
CVE-2019-7212SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access othe...
CVE-2019-7211SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by ...
CVE-2019-11081A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative a...
CVE-2019-11032MEDIUM6.1In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross S...
CVE-2019-10239Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un...
CVE-2019-9724aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File w...
CVE-2019-11498MEDIUM6.5WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depen...
CVE-2019-11490An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendq...
CVE-2019-11487HIGH7.8The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now