2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8455HIGH7.1A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its per...
CVE-2019-8453Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write pe...
CVE-2019-10953HIGH7.5ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers...
CVE-2019-10951HIGH7.8Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow...
CVE-2019-10949Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnera...
CVE-2019-10947HIGH7.8Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflo...
CVE-2019-0228CRITICAL9.8Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XM...
CVE-2019-6153Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-6151Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-6152Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-6150Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-9499HIGH8.1The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validati...
CVE-2019-9498HIGH8.1The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on...
CVE-2019-9497The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element ...
CVE-2019-9496An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps...
CVE-2019-9495LOW3.7The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache...
CVE-2019-9494MEDIUM5.9The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observabl...
CVE-2019-6579CRITICAL9.8A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the...
CVE-2019-6575HIGH7.5A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515...
CVE-2019-6570HIGH8.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking ...
CVE-2019-6568HIGH7.5The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attac...
CVE-2019-3883HIGH7.5In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker...
CVE-2019-3798MEDIUM6Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating u...
CVE-2019-3709HIGH8.3IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remo...
CVE-2019-3708HIGH8.3IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote att...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now