2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0039HIGH8.1If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connectio...
CVE-2019-0038MEDIUM6.5Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial ...
CVE-2019-0037HIGH7.5In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon re...
CVE-2019-0036CRITICAL9.8When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", ...
CVE-2019-0035MEDIUM6.8When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the roo...
CVE-2019-0034Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was withdrawn by its CNA. Further investigatio...
CVE-2019-0033HIGH7.5A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high...
CVE-2019-0032HIGH7.8A password management issue exists where the Organization authentication username and password were stored in plaintext ...
CVE-2019-0031HIGH7.5Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Ju...
CVE-2019-0028HIGH7.5On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP ...
CVE-2019-0019HIGH7.5When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to cras...
CVE-2019-0008CRITICAL9.8A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet For...
CVE-2019-10946An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access chec...
CVE-2019-10945An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param...
CVE-2019-0208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-7139An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca...
CVE-2019-5426MEDIUM4.8In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dyn...
CVE-2019-5425In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the ...
CVE-2019-5424HIGH8.8In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH ...
CVE-2019-7551CRITICAL9Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would en...
CVE-2019-6156In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot...
CVE-2019-6154MEDIUM5.3A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a...
CVE-2019-6287In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in ...
CVE-2019-4013CRITICAL9IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr...
CVE-2019-0199The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive number...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now