2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7161An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.x through build 5704. It uses fixed ciphering keys to ...
CVE-2019-6973Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server ...
CVE-2019-6970Moodle 3.5.x before 3.5.4 allows SSRF.
CVE-2019-6967AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
CVE-2019-6778In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
CVE-2019-6735MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader...
CVE-2019-6734MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto...
CVE-2019-6733MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto...
CVE-2019-6732MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Phanto...
CVE-2019-6731HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit PhantomPDF. Us...
CVE-2019-6730HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i...
CVE-2019-6729HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i...
CVE-2019-6728MEDIUM6.5This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader...
CVE-2019-6727HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader. User i...
CVE-2019-6724The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a ...
CVE-2019-6716An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr...
CVE-2019-6714An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po...
CVE-2019-6702The MasterCard Qkr! app before 5.0.8 for iOS has Missing SSL Certificate Validation. NOTE: this CVE only applies to obso...
CVE-2019-6690HIGH7.5python-gnupg 0.4.3 allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended. To perfo...
CVE-2019-6501In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
CVE-2019-6492SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user de...
CVE-2019-6454MEDIUM5.5An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a va...
CVE-2019-6441An issue was discovered on Shenzhen Coship RT3050 4.0.0.40, RT3052 4.0.0.48, RT7620 10.0.0.49, WM3300 5.0.0.54, and WM33...
CVE-2019-6282ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpag...
CVE-2019-6279ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now