2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9749HIGH7.5An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (s...
CVE-2019-9748In tinysvcmdns through 2018-01-16, an mDNS server processing a crafted packet can perform arbitrary data read operations...
CVE-2019-9747In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while par...
CVE-2019-9746In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_...
CVE-2019-9742gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Char...
CVE-2019-9741MEDIUM6.1An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, a...
CVE-2019-9740MEDIUM6.1An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i...
CVE-2019-9738jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2019-9737MEDIUM6.1Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2019-9736DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
CVE-2019-9735An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x bef...
CVE-2019-9729In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because ...
CVE-2019-5925Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Pro...
CVE-2019-5924HIGH8.8Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the ...
CVE-2019-5923Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attacke...
CVE-2019-5922Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Troj...
CVE-2019-5921Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unsp...
CVE-2019-5920Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the aut...
CVE-2019-5919An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remo...
CVE-2019-5918Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vec...
CVE-2019-5917azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service vi...
CVE-2019-0277SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from...
CVE-2019-0276Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) perfor...
CVE-2019-0275MEDIUM5.4SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7...
CVE-2019-0274SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or f...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now