2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11077HIGH8.8FastAdmin V1.0.0.20190111_beta has a CSRF vulnerability to add a new admin user via the admin/auth/admin/add?dialog=1 UR...
CVE-2019-11072lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (a...
CVE-2019-3943HIGH8.1MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are v...
CVE-2019-11071SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server b...
CVE-2019-11070WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloadin...
CVE-2019-11069Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.
CVE-2019-1003050MEDIUM5.4The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and J...
CVE-2019-1003049HIGH8.1Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would rem...
CVE-2019-0285The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive databas...
CVE-2019-0284SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from a...
CVE-2019-0283SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerabl...
CVE-2019-0282Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, ...
CVE-2019-0279ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BA...
CVE-2019-0278Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in ve...
CVE-2019-9694Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which i...
CVE-2019-6556When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 a...
CVE-2019-3612MEDIUM4.4Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2....
CVE-2019-11068CRITICAL9.8libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permi...
CVE-2019-0229A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vu...
CVE-2019-0216A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript ...
CVE-2019-0044HIGH7.5Receipt of a specific packet on the out-of-band management interface fxp0 may cause the system to crash and restart (vmc...
CVE-2019-0043HIGH7.5In MPLS environments, receipt of a specific SNMP packet may cause the routing protocol daemon (RPD) process to crash and...
CVE-2019-0042MEDIUM4.2Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associat...
CVE-2019-0041HIGH8.6On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopba...
CVE-2019-0040CRITICAL9.1On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets desti...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now