2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1748HIGH7.4A vulnerability in the Cisco Network Plug-and-Play (PnP) agent of Cisco IOS Software and Cisco IOS XE Software could all...
CVE-2019-1747HIGH8.6A vulnerability in the implementation of the Short Message Service (SMS) handling functionality of Cisco IOS Software an...
CVE-2019-1746HIGH7.4A vulnerability in the Cluster Management Protocol (CMP) processing code in Cisco IOS Software and Cisco IOS XE Software...
CVE-2019-1745HIGH7.8A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands that ...
CVE-2019-1743HIGH8.8A vulnerability in the web UI framework of Cisco IOS XE Software could allow an authenticated, remote attacker to make u...
CVE-2019-1742MEDIUM5.3A vulnerability in the web UI of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access sensiti...
CVE-2019-1741HIGH7.5A vulnerability in the Cisco Encrypted Traffic Analytics (ETA) feature of Cisco IOS XE Software could allow an unauthent...
CVE-2019-1740HIGH8.6A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Softw...
CVE-2019-1739HIGH7.5A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Softw...
CVE-2019-1738HIGH7.5A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS Software and Cisco IOS XE Softw...
CVE-2019-1737HIGH8.6A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS Software and Cisco IOS XE sof...
CVE-2019-0161Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local ac...
CVE-2019-0160CRITICAL9.8Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privile...
CVE-2019-1010257CRITICAL9.1An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugi...
CVE-2019-3829MEDIUM5.3A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in...
CVE-2019-10238Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter.
CVE-2019-10237S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&l...
CVE-2019-1000031HIGH7.5A disk space or quota exhaustion issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugin 0.24, 0.25,...
CVE-2019-10233HIGH8.1Teclib GLPI before 9.4.1.1 is affected by a timing attack associated with a cookie.
CVE-2019-10232Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php.
CVE-2019-10231Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occu...
CVE-2019-6536Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocate...
CVE-2019-9860Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Sec...
CVE-2019-9863Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 an...
CVE-2019-9862An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote contr...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now