2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6275Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac...
CVE-2019-6274Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote atta...
CVE-2019-6273download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
CVE-2019-6272Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker...
CVE-2019-6116HIGH7.8In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to ...
CVE-2019-5885Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable val...
CVE-2019-5729Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-...
CVE-2019-5723An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather t...
CVE-2019-5722An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handl...
CVE-2019-5417A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary file...
CVE-2019-5416A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitr...
CVE-2019-5415HIGH7.5A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the ...
CVE-2019-5414If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands du...
CVE-2019-5413An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
CVE-2019-5011MEDIUM5.5An exploitable privilege escalation vulnerability exists in the helper service CleanMyMac X, version 4.20, due to improp...
CVE-2019-4094HIGH7.8IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared librari...
CVE-2019-3862HIGH7.3An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exi...
CVE-2019-3859CRITICAL9.1An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req...
CVE-2019-3832MEDIUM5.5It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of ...
CVE-2019-3497HIGH8.8An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagn...
CVE-2019-3496HIGH8.8An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Dia...
CVE-2019-3495HIGH8.8An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable ...
CVE-2019-0191Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in ...
CVE-2019-6149MEDIUM6.7An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 ...
CVE-2019-5616MEDIUM5.3CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controll...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now