2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9771HIGH7.5An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_conver...
CVE-2019-9770HIGH7.5An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_deco...
CVE-2019-9769PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad...
CVE-2019-9768Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta...
CVE-2019-9767Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ...
CVE-2019-9766Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ...
CVE-2019-9765In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, ...
CVE-2019-9762A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnera...
CVE-2019-9761An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network...
CVE-2019-9760FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont...
CVE-2019-9754An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byt...
CVE-2019-9752MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4....
CVE-2019-9751An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is ...
CVE-2019-6601MEDIUM5.5In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd pr...
CVE-2019-6600MEDIUM6.1In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authenticati...
CVE-2019-6599In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed p...
CVE-2019-6598In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1...
CVE-2019-6597In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenti...
CVE-2019-6596In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragment...
CVE-2019-3785HIGH8.1Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote auth...
CVE-2019-3716HIGH7.8RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password m...
CVE-2019-3715HIGH7.8RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logg...
CVE-2019-3711MEDIUM5.8RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious...
CVE-2019-1723CRITICAL9.8A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker t...
CVE-2019-9750In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now