2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19469HIGH8.8In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrate...
CVE-2019-19468HIGH7.8Free Photo Viewer 1.3 allows remote attackers to execute arbitrary code via a crafted BMP and/or TIFF file that triggers...
CVE-2019-19396HIGH7.5illumos, as used in OmniOS Community Edition before r151030y, allows a kernel crash via an application with multiple thr...
CVE-2019-5268HIGH8.1Some Huawei home routers have an input validation vulnerability. Due to input parameter is not correctly verified, an at...
CVE-2019-5269HIGH7.8Some Huawei home routers have an improper authorization vulnerability. Due to improper authorization of certain programs...
CVE-2019-5232HIGH7.5There is a use of insufficiently random values vulnerability in Huawei ViewPoint products. An unauthenticated, remote at...
CVE-2019-5225HIGH7.8P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions ea...
CVE-2019-5218HIGH8.8There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently ...
CVE-2019-5210HIGH7.8Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(...
CVE-2019-18922HIGH7.5A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] al...
CVE-2019-16767HIGH7.2The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance ...
CVE-2019-19378HIGH7.8In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in ind...
CVE-2019-16766HIGH8.8When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into t...
CVE-2019-19377HIGH7.8In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can le...
CVE-2019-19372HIGH7.5A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in...
CVE-2019-18276HIGH7.8An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run wit...
CVE-2019-18247HIGH7.5An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 se...
CVE-2019-6673HIGH7.5On versions 15.0.0-15.0.1 and 14.0.0-14.1.2, when the BIG-IP is configured in HTTP/2 Full Proxy mode, specifically craft...
CVE-2019-6672HIGH7.5On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, and 13.1.0-13.1.3.1, when bad-actor detection is configured on a wildcard vi...
CVE-2019-6671HIGH7.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory...
CVE-2019-6669HIGH7.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed ...
CVE-2019-6667HIGH7.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under ce...
CVE-2019-6666HIGH7.5On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file ...
CVE-2019-6674HIGH7.5On F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2, TMM may crash when processing SSLO data in a service-chaining co...
CVE-2019-15705HIGH7.5An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and belo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now