2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-14812HIGH7.8A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly...
CVE-2019-10216HIGH7.8In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scr...
CVE-2019-14867HIGH8.8A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ...
CVE-2019-17590HIGH8.8The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it al...
CVE-2019-16387HIGH8.1PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li...
CVE-2019-16255HIGH8.1Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "c...
CVE-2019-16201HIGH7.5WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expressi...
CVE-2019-18679HIGH7.5An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to in...
CVE-2019-18676HIGH7.5An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffe...
CVE-2019-18455HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries....
CVE-2019-7319HIGH8.3An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBa...
CVE-2019-6477HIGH7.5With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query receiv...
CVE-2019-4387HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker c...
CVE-2019-18457HIGH8.8An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It ...
CVE-2019-19275HIGH7.5typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python in...
CVE-2019-19274HIGH7.5typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Pyth...
CVE-2019-18460HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature prov...
CVE-2019-14853HIGH7.5An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatu...
CVE-2019-14890HIGH8.4A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames an...
CVE-2019-19272HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable init...
CVE-2019-19271HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a clie...
CVE-2019-19270HIGH7.5An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL...
CVE-2019-15972HIGH8.8A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat...
CVE-2019-15956HIGH8.8A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could a...
CVE-2019-15288HIGH8.8A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco R...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now