2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20902HIGH7.5Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from befor...
CVE-2019-20922HIGH7.5Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be...
CVE-2019-20921MEDIUM6.1bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. Th...
CVE-2019-20920HIGH8.1Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to prope...
CVE-2019-18991MEDIUM5.4A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d...
CVE-2019-18990MEDIUM5.4A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RT...
CVE-2019-18989MEDIUM5.4A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending ...
CVE-2019-17098MEDIUM6.5Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacke...
CVE-2019-16212HIGH8.8A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP ...
CVE-2019-16211CRITICAL9.8Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability.
CVE-2019-11556MEDIUM6.1Pagure before 5.6 allows XSS via the templates/blame.html blame view.
CVE-2019-7178HIGH7.2Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup.
CVE-2019-7177HIGH7.2Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
CVE-2019-1983MEDIUM5.3A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA...
CVE-2019-1947HIGH8.6A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA...
CVE-2019-1888HIGH7.2A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an...
CVE-2019-1736MEDIUM6.6A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker t...
CVE-2019-16028CRITICAL9.8A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthen...
CVE-2019-16025MEDIUM4.8A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to condu...
CVE-2019-16023HIGH7.5Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cis...
CVE-2019-16021HIGH7.5Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cis...
CVE-2019-16019HIGH8.6Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cis...
CVE-2019-16017MEDIUM6.8A vulnerability in the Operations, Administration, Maintenance and Provisioning (OAMP) OpsConsole Server for Cisco Unifi...
CVE-2019-16009HIGH8.8A vulnerability in the web UI of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to ...
CVE-2019-16007HIGH7.1A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now