2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-12410HIGH7.5While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0....
CVE-2019-12408HIGH7.5It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0...
CVE-2019-17661HIGH8.8A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to ...
CVE-2019-17327HIGH7.2JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input paramete...
CVE-2019-16209HIGH7.4A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to per...
CVE-2019-16208HIGH7.5Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptogr...
CVE-2019-16207HIGH7.8Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access...
CVE-2019-16205HIGH8.8A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID....
CVE-2019-10222HIGH7.5A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated ...
CVE-2019-3465HIGH8.8Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validat...
CVE-2019-18813HIGH7.5A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows a...
CVE-2019-18812HIGH7.5A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows att...
CVE-2019-18810HIGH7.5A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in t...
CVE-2019-18807HIGH7.5Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux ke...
CVE-2019-17605HIGH8.8A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidat...
CVE-2019-16877HIGH8.8Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
CVE-2019-16876HIGH7.5Portainer before 1.22.1 allows Directory Traversal.
CVE-2019-12331HIGH8.8PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if ...
CVE-2019-18804HIGH7.5DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
CVE-2019-15004HIGH7.5The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ...
CVE-2019-18411HIGH8.8Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are att...
CVE-2019-5125HIGH7.8An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially cra...
CVE-2019-5100HIGH7.8An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A speciall...
CVE-2019-5099HIGH7.8An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially craf...
CVE-2019-5084HIGH7.8An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A special...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now