2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18422 | HIGH | 8.8 | 1.8% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privilege... |
| CVE-2019-18421 | HIGH | 7.5 | 1.7% | Oct 31, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging ra... |
| CVE-2019-18635 | HIGH | 7.5 | 2.1% | Oct 30, 2019 | An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a... |
| CVE-2019-17323 | HIGH | 8.8 | 1.6% | Oct 30, 2019 | ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of... |
| CVE-2019-18206 | HIGH | 8.8 | 0.5% | Oct 30, 2019 | A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary ... |
| CVE-2019-18204 | HIGH | 8.8 | 1.7% | Oct 30, 2019 | Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve... |
| CVE-2019-15682 | HIGH | 7.5 | 1.4% | Oct 30, 2019 | RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial... |
| CVE-2019-7620 | HIGH | 7.5 | 1.5% | Oct 30, 2019 | Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthe... |
| CVE-2019-9926 | HIGH | 8.8 | 1.9% | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code throu... |
| CVE-2019-9757 | HIGH | 7.5 | 37.3% | Oct 29, 2019 | An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-... |
| CVE-2019-6851 | HIGH | 7.5 | 29.9% | Oct 29, 2019 | A CWE-538: File and Directory Information Exposure vulnerability exists in Modicon M580, Modicon M340, Modicon Premium ,... |
| CVE-2019-6850 | HIGH | 7.5 | 1.7% | Oct 29, 2019 | A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic... |
| CVE-2019-6849 | HIGH | 7.5 | 1.7% | Oct 29, 2019 | A CWE-200: Information Exposure vulnerability exists in Modicon M580, Modicon BMENOC 0311, and Modicon BMENOC 0321, whic... |
| CVE-2019-6848 | HIGH | 8.6 | 33.0% | Oct 29, 2019 | A CWE-755: Improper Handling of Exceptional Conditions vulnerability exists in Modicon M580 CPU (BMEx58*) and Modicon M5... |
| CVE-2019-6845 | HIGH | 7.5 | 1.1% | Oct 29, 2019 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists in Modicon M580, Modicon M340, Modicon P... |
| CVE-2019-3979 | HIGH | 7.5 | 0.9% | Oct 29, 2019 | RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router a... |
| CVE-2019-3978 | HIGH | 7.5 | 10.3% | Oct 29, 2019 | RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri... |
| CVE-2019-3977 | HIGH | 7.5 | 1.1% | Oct 29, 2019 | RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download... |
| CVE-2019-3976 | HIGH | 8.8 | 1.7% | Oct 29, 2019 | RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerabi... |
| CVE-2019-18608 | HIGH | 7.5 | 1.0% | Oct 29, 2019 | Cezerin v0.33.0 allows unauthorized order-information modification because certain internal attributes can be overwritte... |
| CVE-2019-18602 | HIGH | 7.5 | 1.5% | Oct 29, 2019 | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized s... |
| CVE-2019-18601 | HIGH | 7.5 | 1.4% | Oct 29, 2019 | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote ... |
| CVE-2019-16647 | HIGH | 7.2 | 2.0% | Oct 29, 2019 | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows. |
| CVE-2019-15681 | HIGH | 7.5 | 3.3% | Oct 29, 2019 | LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which... |
| CVE-2019-15680 | HIGH | 7.5 | 2.8% | Oct 29, 2019 | TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now