2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18242 | HIGH | 7.5 | 1.3% | Mar 24, 2020 | In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, ... |
| CVE-2019-4681 | MEDIUM | 6.1 | 0.7% | Mar 24, 2020 | IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows user... |
| CVE-2019-4553 | HIGH | 7.5 | 0.8% | Mar 24, 2020 | IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an att... |
| CVE-2019-17565 | CRITICAL | 9.8 | 3.1% | Mar 23, 2020 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at... |
| CVE-2019-17559 | CRITICAL | 9.8 | 3.1% | Mar 23, 2020 | There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling at... |
| CVE-2019-6558 | HIGH | 7.5 | 1.1% | Mar 23, 2020 | In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the ... |
| CVE-2019-6560 | CRITICAL | 9.1 | 1.1% | Mar 23, 2020 | In Auto-Maskin RP210E Versions 3.7 and prior, DCU210E Versions 3.7 and prior and Marine Observer Pro (Android App), the ... |
| CVE-2019-20627 | CRITICAL | 9.8 | 2.3% | Mar 23, 2020 | AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. |
| CVE-2019-20626 | MEDIUM | 6.5 | 0.7% | Mar 23, 2020 | The remote keyless system on Honda HR-V 2017 vehicles sends the same RF signal for each door-open request, which might a... |
| CVE-2019-19034 | HIGH | 7.2 | 6.0% | Mar 23, 2020 | Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username ... |
| CVE-2019-4718 | MEDIUM | 5.4 | 0.7% | Mar 23, 2020 | IBM Jazz for Service Management 3.13 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2019-5186 | HIGH | 7 | 0.8% | Mar 23, 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit... |
| CVE-2019-5185 | HIGH | 7 | 0.8% | Mar 23, 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit... |
| CVE-2019-5184 | HIGH | 7.8 | 0.8% | Mar 23, 2020 | An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A spe... |
| CVE-2019-19964 | LOW | 2.7 | 0.9% | Mar 23, 2020 | On NETGEAR GS728TPS devices through 5.3.0.35, a remote attacker having network connectivity to the web-administration pa... |
| CVE-2019-15510 | MEDIUM | 6.1 | 3.2% | Mar 23, 2020 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration... |
| CVE-2019-18936 | HIGH | 7.5 | 1.5% | Mar 21, 2020 | UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches ... |
| CVE-2019-17185 | HIGH | 7.5 | 2.2% | Mar 21, 2020 | In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. Th... |
| CVE-2019-12767 | CRITICAL | 9.8 | 2.1% | Mar 21, 2020 | An issue was discovered on D-Link DAP-1650 devices before 1.04B02_J65H Hot Fix. Attackers can execute arbitrary commands... |
| CVE-2019-11574 | CRITICAL | 9.8 | 1.5% | Mar 20, 2020 | An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php ... |
| CVE-2019-18860 | MEDIUM | 6.1 | 5.5% | Mar 20, 2020 | Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.c... |
| CVE-2019-18641 | CRITICAL | 9.8 | 3.3% | Mar 20, 2020 | Rock RMS before 1.8.6 mishandles vCard access control within the People/GetVCard/REST controller. |
| CVE-2019-16528 | HIGH | 7.5 | 1.3% | Mar 20, 2020 | An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attacker... |
| CVE-2019-15522 | CRITICAL | 9.8 | 1.9% | Mar 20, 2020 | An issue was discovered in LINBIT csync2 through 2.0. csync_daemon_session in daemon.c neglects to force a failure of a ... |
| CVE-2019-13463 | MEDIUM | 6.1 | 1.1% | Mar 20, 2020 | An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress all... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now