2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20801MEDIUM5.3An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al...
CVE-2019-20800CRITICAL9.8In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in...
CVE-2019-20799HIGH7.5In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work ...
CVE-2019-20798HIGH8.4An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displa...
CVE-2019-20797HIGH7.5An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for...
CVE-2019-20390HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to r...
CVE-2019-20389MEDIUM6.1An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can i...
CVE-2019-19721HIGH7.8An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows re...
CVE-2019-18666CRITICAL9.8An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without autho...
CVE-2019-17572MEDIUM5.3In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topi...
CVE-2019-17562CRITICAL9.8A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all vers...
CVE-2019-13023MEDIUM6.5An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD...
CVE-2019-13022CRITICAL9.8Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorit...
CVE-2019-13021MEDIUM6.5The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem,...
CVE-2019-15083MEDIUM6.1Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst...
CVE-2019-2388MEDIUM5.3In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access l...
CVE-2019-9682HIGH8.1Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compati...
CVE-2019-15880CRITICAL9.8In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocat...
CVE-2019-15879HIGH7.4In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a...
CVE-2019-15878HIGH7.8In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use...
CVE-2019-16112HIGH8.8TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java objec...
CVE-2019-4478MEDIUM6.5IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information th...
CVE-2019-5500HIGH7.5Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthentic...
CVE-2019-4667MEDIUM5.9IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure ...
CVE-2019-19162HIGH7.8A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system ru...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now