2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9053An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve...
CVE-2019-7646CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package...
CVE-2019-9764HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the prod...
CVE-2019-10063Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions sin...
CVE-2019-8981tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because t...
CVE-2019-7715An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell ha...
CVE-2019-7714An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Auth...
CVE-2019-7713An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. There is a heap-b...
CVE-2019-7712An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RT...
CVE-2019-7711An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented ...
CVE-2019-10061utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection....
CVE-2019-10060The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allow...
CVE-2019-7642HIGH7.5D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can re...
CVE-2019-6538MEDIUM6.5The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v...
CVE-2019-0204HIGH7.8A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru...
CVE-2019-10044Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to a...
CVE-2019-7613HIGH7.5Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain charact...
CVE-2019-7612CRITICAL9.8A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If ...
CVE-2019-7611HIGH8.1A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Le...
CVE-2019-7610Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance...
CVE-2019-7609CRITICAL10Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker...
CVE-2019-7608Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to o...
CVE-2019-4046HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handlin...
CVE-2019-3879HIGH8.1It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com...
CVE-2019-3874MEDIUM6.5The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use th...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now