2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17210 | HIGH | 7.5 | 1.0% | Nov 4, 2019 | A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString()... |
| CVE-2019-13496 | HIGH | 8.1 | 0.8% | Nov 4, 2019 | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the... |
| CVE-2019-18684 | HIGH | 7 | 0.3% | Nov 4, 2019 | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo pr... |
| CVE-2019-18683 | HIGH | 7 | 1.0% | Nov 4, 2019 | An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile... |
| CVE-2019-18680 | HIGH | 7.5 | 3.6% | Nov 4, 2019 | An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_so... |
| CVE-2019-0350 | HIGH | 7.5 | 1.1% | Nov 4, 2019 | SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which cras... |
| CVE-2019-18665 | HIGH | 7.5 | 14.9% | Nov 2, 2019 | The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. |
| CVE-2019-18661 | HIGH | 7.5 | 1.5% | Nov 2, 2019 | Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 ... |
| CVE-2019-6470 | HIGH | 7.5 | 8.8% | Nov 1, 2019 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 m... |
| CVE-2019-15588 | HIGH | 7.2 | 5.6% | Nov 1, 2019 | There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attac... |
| CVE-2019-18230 | HIGH | 7.5 | 1.1% | Oct 31, 2019 | Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product ... |
| CVE-2019-18228 | HIGH | 7.5 | 2.1% | Oct 31, 2019 | Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a... |
| CVE-2019-18227 | HIGH | 7.5 | 3.1% | Oct 31, 2019 | Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive dat... |
| CVE-2019-16906 | HIGH | 7.5 | 2.1% | Oct 31, 2019 | An issue was discovered in the Infosysta "In-App & Desktop Notifications" app 1.6.13_J8 for Jira. By using plugins/servl... |
| CVE-2019-16675 | HIGH | 7.8 | 3.3% | Oct 31, 2019 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86.... |
| CVE-2019-5043 | HIGH | 7.5 | 0.7% | Oct 31, 2019 | An exploitable denial-of-service vulnerability exists in the Weave daemon of the Nest Cam IQ Indoor, version 4620002. A ... |
| CVE-2019-5030 | HIGH | 8.8 | 2.9% | Oct 31, 2019 | A buffer overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server Docum... |
| CVE-2019-5010 | HIGH | 7.5 | 20.7% | Oct 31, 2019 | An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6... |
| CVE-2019-5150 | HIGH | 8.1 | 1.5% | Oct 31, 2019 | An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially ... |
| CVE-2019-18396 | HIGH | 7.2 | 16.2% | Oct 31, 2019 | An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Comm... |
| CVE-2019-15710 | HIGH | 7.2 | 1.9% | Oct 31, 2019 | An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow... |
| CVE-2019-12612 | HIGH | 7.8 | 0.3% | Oct 31, 2019 | An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that allows an attacker to pass arbitra... |
| CVE-2019-3421 | HIGH | 8 | 1.1% | Oct 31, 2019 | The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection v... |
| CVE-2019-18368 | HIGH | 7.3 | 1.0% | Oct 31, 2019 | In JetBrains Toolbox App before 1.15.5666 for Windows, privilege escalation was possible. |
| CVE-2019-18423 | HIGH | 8.8 | 2.1% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now