2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-8170HIGH8.8Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8168HIGH7.5Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8166HIGH8.8Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8165HIGH8.8Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8164HIGH7.5Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8162HIGH8.1Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-6476HIGH7.5A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder re...
CVE-2019-6475HIGH7.5Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zo...
CVE-2019-18192HIGH7.8GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user...
CVE-2019-15065HIGH7.5A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific c...
CVE-2019-13412HIGH7.5A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific c...
CVE-2019-13410HIGH7.5TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacke...
CVE-2019-17119HIGH8.8Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticate...
CVE-2019-15627HIGH7.1Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w...
CVE-2019-15626HIGH7.5The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit ini...
CVE-2019-13657HIGH8.8CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that...
CVE-2019-17118HIGH8.8A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user ...
CVE-2019-17117HIGH8.8A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authentica...
CVE-2019-16917HIGH8.8WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection th...
CVE-2019-14287HIGH8.8In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se...
CVE-2019-11284HIGH8.6Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remot...
CVE-2019-11253HIGH7.5Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1...
CVE-2019-15850HIGH8.8eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated...
CVE-2019-15849HIGH7.3eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the vi...
CVE-2019-14423HIGH8.8A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now