2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-17327HIGH7.2JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input paramete...
CVE-2019-16209HIGH7.4A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to per...
CVE-2019-16208HIGH7.5Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptogr...
CVE-2019-16207HIGH7.8Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access...
CVE-2019-16205HIGH8.8A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID....
CVE-2019-10222HIGH7.5A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated ...
CVE-2019-3465HIGH8.8Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validat...
CVE-2019-18813HIGH7.5A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows a...
CVE-2019-18812HIGH7.5A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows att...
CVE-2019-18810HIGH7.5A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in t...
CVE-2019-18807HIGH7.5Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux ke...
CVE-2019-17605HIGH8.8A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidat...
CVE-2019-16877HIGH8.8Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4).
CVE-2019-16876HIGH7.5Portainer before 1.22.1 allows Directory Traversal.
CVE-2019-12331HIGH8.8PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if ...
CVE-2019-18804HIGH7.5DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
CVE-2019-15004HIGH7.5The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ...
CVE-2019-18411HIGH8.8Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are att...
CVE-2019-5125HIGH7.8An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially cra...
CVE-2019-5100HIGH7.8An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A speciall...
CVE-2019-5099HIGH7.8An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially craf...
CVE-2019-5084HIGH7.8An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A special...
CVE-2019-6120HIGH7.5An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address a...
CVE-2019-2246HIGH7.8Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel...
CVE-2019-10529HIGH8.1Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now