2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19598HIGH8.8D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP...
CVE-2019-19597HIGH8.8D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via sh...
CVE-2019-19590HIGH7.8In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at ...
CVE-2019-19588HIGH7.5The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a ...
CVE-2019-19553HIGH7.5In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/as...
CVE-2019-19522HIGH7.8OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to beco...
CVE-2019-19520HIGH7.8xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir...
CVE-2019-19519HIGH7.8In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is ...
CVE-2019-16753HIGH7.5An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is...
CVE-2019-19364HIGH7.8A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and Cata...
CVE-2019-18346HIGH8.8A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, th...
CVE-2019-17555HIGH7.5The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it t...
CVE-2019-7201HIGH7.8An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul...
CVE-2019-11937HIGH7.5In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhausti...
CVE-2019-11923HIGH7.5In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no max...
CVE-2019-15638HIGH7.8COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element.
CVE-2019-14909HIGH8.3A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any pa...
CVE-2019-18850HIGH7.5TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding ...
CVE-2019-5164HIGH7.8An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafte...
CVE-2019-5163HIGH7.5An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti...
CVE-2019-5133HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library....
CVE-2019-5132HIGH8.8An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear...
CVE-2019-5112HIGH8.8Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server....
CVE-2019-5111HIGH8.8Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server....
CVE-2019-5110HIGH8.8Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web r...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now