2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19000 | MEDIUM | 6.5 | 1.1% | Apr 2, 2020 | For ABB eSOMS 4.0 to 6.0.3, the Cache-Control and Pragma HTTP header(s) have not been properly configured within the app... |
| CVE-2019-14868 | HIGH | 7.8 | 1.4% | Apr 2, 2020 | In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use t... |
| CVE-2019-20635 | MEDIUM | 6.1 | 0.9% | Apr 2, 2020 | codeBeamer before 9.5.0-RC3 does not properly restrict the ability to execute custom Java code and access the Java class... |
| CVE-2019-7017 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7016 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7015 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7014 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7013 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7012 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7011 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7010 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7009 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7008 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-6999 | — | — | — | Apr 2, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-17564 | CRITICAL | 9.8 | 35.6% | Apr 1, 2020 | Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST ... |
| CVE-2019-9163 | CRITICAL | 9.8 | 2.3% | Apr 1, 2020 | The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbit... |
| CVE-2019-11254 | MEDIUM | 6.5 | 2.3% | Apr 1, 2020 | The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an aut... |
| CVE-2019-3945 | HIGH | 7.5 | 1.1% | Apr 1, 2020 | Web server running on Parrot ANAFI can be crashed due to the SDK command "Common_CurrentDateTime" being sent to control ... |
| CVE-2019-3944 | HIGH | 7.5 | 1.5% | Apr 1, 2020 | Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect... |
| CVE-2019-3942 | HIGH | 7.5 | 1.4% | Apr 1, 2020 | Advantech WebAccess 8.3.4 does not properly restrict an RPC call that allows unauthenticated, remote users to read files... |
| CVE-2019-13495 | MEDIUM | 5.4 | 0.6% | Mar 31, 2020 | In firmware version 4.50 of Zyxel XGS2210-52HP, multiple stored cross-site scripting (XSS) issues allows remote authenti... |
| CVE-2019-14905 | MEDIUM | 5.6 | 0.7% | Mar 31, 2020 | A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear... |
| CVE-2019-10180 | MEDIUM | 4.8 | 0.7% | Mar 31, 2020 | A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sani... |
| CVE-2019-14880 | CRITICAL | 9.1 | 1.1% | Mar 31, 2020 | A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 p... |
| CVE-2019-2391 | MEDIUM | 5.4 | 0.9% | Mar 31, 2020 | Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now