2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-1663CRITICAL9.8A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless...
CVE-2019-9215CRITICAL9.8In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
CVE-2019-9201CRITICAL9.8Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info...
CVE-2019-9195CRITICAL9.8util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory t...
CVE-2019-9169CRITICAL9.8In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer ove...
CVE-2019-9123CRITICAL9.8An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password.
CVE-2019-8996CRITICAL9.8In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow.
CVE-2019-7164CRITICAL9.8SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
CVE-2019-4059CRITICAL9.8IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker c...
CVE-2019-8341CRITICAL9.8An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where...
CVE-2019-5916CRITICAL9.8Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch ...
CVE-2019-6543CRITICAL9.8AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)...
CVE-2019-6533CRITICAL9.1Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100...
CVE-2019-6527CRITICAL9.8PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able t...
CVE-2019-7653CRITICAL9.8The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the curr...
CVE-2019-6139CRITICAL9.8Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. ...
CVE-2019-4008CRITICAL9.8API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in...
CVE-2019-3822CRITICAL9.8libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an ...
CVE-2019-3464CRITICAL9.8Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restri...
CVE-2019-3463CRITICAL9.8Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell t...
CVE-2019-1000006CRITICAL9.8RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in s...
CVE-2019-1651CRITICAL9.9A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a ...
CVE-2019-3773CRITICAL9.8Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XM...
CVE-2019-0022CRITICAL10Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take f...
CVE-2019-0020CRITICAL10Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now