2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9966XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have...
CVE-2019-9965XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un...
CVE-2019-9964XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un...
CVE-2019-9963XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un...
CVE-2019-9962XnView MP 0.93.1 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have un...
CVE-2019-9960The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relati...
CVE-2019-9956In ImageMagick 7.0.8-35 Q16, there is a stack-based buffer overflow in the function PopHexPixel of coders/ps.c, which al...
CVE-2019-9948CRITICAL9.1urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypas...
CVE-2019-9947MEDIUM6.1An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i...
CVE-2019-9945SoftNAS Cloud 4.2.0 and 4.2.1 allows remote command execution. The NGINX default configuration file has a check to verif...
CVE-2019-9942LOW3.7A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it...
CVE-2019-9649An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote att...
CVE-2019-1766HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1765HIGH8.1A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1764HIGH8.1A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1763HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8...
CVE-2019-1716HIGH7.5A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7...
CVE-2019-9648An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exis...
CVE-2019-4052HIGH7.5IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered...
CVE-2019-4035MEDIUM5.4IBM Content Navigator 3.0CD could allow attackers to direct web traffic to a malicious site. If attackers make a fake IB...
CVE-2019-9939The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open"...
CVE-2019-9938The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open"...
CVE-2019-9937In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL P...
CVE-2019-9936In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5Ha...
CVE-2019-9927Caret before 2019-02-22 allows Remote Code Execution.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now