2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5893Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.
CVE-2019-5892bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x bef...
CVE-2019-5887An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not ...
CVE-2019-5886An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lo...
CVE-2019-5884MEDIUM5.9php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or o...
CVE-2019-5882Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer.
CVE-2019-3498In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elem...
CVE-2019-5748In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
CVE-2019-5747HIGH7.5An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP clien...
CVE-2019-0542HIGH8.8A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Re...
CVE-2019-3581HIGH7.5Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus...
CVE-2019-5725qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstr...
CVE-2019-5721In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by cha...
CVE-2019-5719In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors...
CVE-2019-5718In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was add...
CVE-2019-5717In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/...
CVE-2019-5716In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c b...
CVE-2019-0622An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication r...
CVE-2019-0588MEDIUM6.5An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors m...
CVE-2019-0586CRITICAL9.8A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o...
CVE-2019-0585A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo...
CVE-2019-0584A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0583A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0582HIGH7.8A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0581A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now