2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9509 | MEDIUM | 5.4 | 0.9% | Mar 30, 2020 | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST paramet... |
| CVE-2019-9508 | LOW | 3.5 | 0.6% | Mar 30, 2020 | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authent... |
| CVE-2019-9507 | HIGH | 7.2 | 2.1% | Mar 30, 2020 | The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the applica... |
| CVE-2019-19913 | MEDIUM | 4.8 | 0.7% | Mar 30, 2020 | In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter. |
| CVE-2019-19912 | MEDIUM | 4.8 | 0.8% | Mar 30, 2020 | In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature a... |
| CVE-2019-19606 | CRITICAL | 9.8 | 2.4% | Mar 30, 2020 | X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary... |
| CVE-2019-19605 | CRITICAL | 9.8 | 2.1% | Mar 30, 2020 | X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or... |
| CVE-2019-20634 | LOW | 3.7 | 1.6% | Mar 30, 2020 | An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email he... |
| CVE-2019-17561 | HIGH | 7.5 | 1.6% | Mar 30, 2020 | The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded... |
| CVE-2019-17560 | CRITICAL | 9.1 | 2.0% | Mar 30, 2020 | The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This... |
| CVE-2019-7755 | HIGH | 8.8 | 2.1% | Mar 30, 2020 | In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement fil... |
| CVE-2019-5105 | HIGH | 7.5 | 2.2% | Mar 26, 2020 | An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solu... |
| CVE-2019-15796 | MEDIUM | 4.7 | 0.5% | Mar 26, 2020 | Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py... |
| CVE-2019-15795 | MEDIUM | 4.7 | 0.4% | Mar 26, 2020 | python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/... |
| CVE-2019-18626 | MEDIUM | 4.3 | 0.6% | Mar 25, 2020 | Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an... |
| CVE-2019-7630 | HIGH | 7.2 | 3.1% | Mar 25, 2020 | An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instr... |
| CVE-2019-7245 | HIGH | 7.2 | 2.4% | Mar 25, 2020 | An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z before 2.23.0. The vulnerable driver exposes a wrmsr instructi... |
| CVE-2019-7244 | HIGH | 7.2 | 2.4% | Mar 25, 2020 | An issue was discovered in kerneld.sys in AIDA64 before 5.99. The vulnerable driver exposes a wrmsr instruction via IOCT... |
| CVE-2019-7240 | HIGH | 7.2 | 2.4% | Mar 25, 2020 | An issue was discovered in WinRing0x64.sys in Moo0 System Monitor 1.83. The vulnerable driver exposes a wrmsr instructio... |
| CVE-2019-20633 | MEDIUM | 5.5 | 1.0% | Mar 25, 2020 | GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c t... |
| CVE-2019-19127 | HIGH | 8.1 | 1.3% | Mar 25, 2020 | An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its de... |
| CVE-2019-4001 | HIGH | 7.8 | 0.6% | Mar 24, 2020 | Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJ... |
| CVE-2019-19347 | — | — | — | Mar 24, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2019-20625 | LOW | 3.3 | 0.1% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs dri... |
| CVE-2019-20624 | MEDIUM | 5.3 | 0.3% | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now