2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-10692CRITICAL9.8In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize...
CVE-2019-5891CRITICAL9.8An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to ob...
CVE-2019-10661CRITICAL9.8On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password.
CVE-2019-10655CRITICAL9.8Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0....
CVE-2019-9918CRITICAL9.1An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries...
CVE-2019-10269CRITICAL9.8BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bnts...
CVE-2019-9204CRITICAL9.8SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL...
CVE-2019-9203CRITICAL9.8Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API.
CVE-2019-9165CRITICAL9.8SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API wh...
CVE-2019-1003041CRITICAL9.8A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary ...
CVE-2019-1003040CRITICAL9.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary c...
CVE-2019-0160CRITICAL9.8Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privile...
CVE-2019-1010257CRITICAL9.1An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugi...
CVE-2019-5420CRITICAL9.8A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th...
CVE-2019-10125CRITICAL9.8An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_...
CVE-2019-6569CRITICAL9.1The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into t...
CVE-2019-10068CRITICAL9.8An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions...
CVE-2019-7612CRITICAL9.8A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If ...
CVE-2019-7609CRITICAL10Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker...
CVE-2019-3396CRITICAL9.8The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers...
CVE-2019-9948CRITICAL9.1urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypas...
CVE-2019-7238CRITICAL9.8Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
CVE-2019-3859CRITICAL9.1An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req...
CVE-2019-9775CRITICAL9.1An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_C...
CVE-2019-9774CRITICAL9.1An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at b...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now