2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3861MEDIUM5An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value gre...
CVE-2019-3860MEDIUM5An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed...
CVE-2019-3857HIGH8.8An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS...
CVE-2019-3856HIGH8.8An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way ...
CVE-2019-3838MEDIUM5.5It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A ...
CVE-2019-3835MEDIUM5.5It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A speciall...
CVE-2019-3396CRITICAL9.8The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers...
CVE-2019-3395The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), f...
CVE-2019-10042The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th...
CVE-2019-10041The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th...
CVE-2019-10040The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th...
CVE-2019-10039The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th...
CVE-2019-10012HIGH7.5Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code...
CVE-2019-10011ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attack...
CVE-2019-3863HIGH7.5A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple...
CVE-2019-3841HIGH7.4Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when ...
CVE-2019-3831MEDIUM6.7A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function ...
CVE-2019-3827HIGH7An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modif...
CVE-2019-3810MEDIUM6.1A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers...
CVE-2019-3809MEDIUM6.5A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed...
CVE-2019-3808MEDIUM5.4A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers...
CVE-2019-6240An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal.
CVE-2019-3484Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3483Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7.
CVE-2019-3482Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now