2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7006MEDIUM5.5Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a lo...
CVE-2019-9201CRITICAL9.8Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info...
CVE-2019-9200A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for exa...
CVE-2019-9199PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can ...
CVE-2019-9195CRITICAL9.8util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory t...
CVE-2019-9194elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
CVE-2019-9192In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled ...
CVE-2019-9191The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secre...
CVE-2019-7392An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a re...
CVE-2019-9184SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr...
CVE-2019-6595Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI.
CVE-2019-6594On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not ...
CVE-2019-6593On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to ...
CVE-2019-6592On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or ser...
CVE-2019-9182There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by p...
CVE-2019-9181SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the ....
CVE-2019-9169CRITICAL9.8In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer ove...
CVE-2019-9168WooCommerce before 3.5.5 allows XSS via a Photoswipe caption.
CVE-2019-9162HIGH7.8In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ...
CVE-2019-6266Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and ...
CVE-2019-6265The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 ar...
CVE-2019-9152An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H...
CVE-2019-9151An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in ...
CVE-2019-9146Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell...
CVE-2019-9145An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now