2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-25248HIGH8.7Beward N100 M2.1.6.04C014 contains an unauthenticated vulnerability that allows remote attackers to access live video st...
CVE-2019-25246HIGH8.8Beward N100 H.264 VGA IP Camera M2.1.6 contains an authenticated file disclosure vulnerability that allows attackers to ...
CVE-2019-25245HIGH8.8Ross Video DashBoard 8.5.1 contains an elevation of privileges vulnerability that allows authenticated users to modify e...
CVE-2019-25243HIGH8.8FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php sc...
CVE-2019-25239HIGH8.7V-SOL GPON/EPON OLT Platform 2.03 contains an unauthenticated information disclosure vulnerability that allows attackers...
CVE-2019-25229HIGH8.8An unrestricted file upload vulnerability in Kentico Xperience allows authenticated users with 'Read data' permissions t...
CVE-2019-25227HIGH8.7Tellion HN-2204AP routers contain an unauthenticated configuration disclosure vulnerability in the /cgi-bin/system_confi...
CVE-2019-25226HIGH8.7Dongyoung Media DM-AP240T/W wireless access points contain an unauthenticated configuration disclosure vulnerability in ...
CVE-2019-16536HIGH8.8Stack overflow leading to DoS can be triggered by a malicious authenticated client in Clickhouse before 19.14.3.3.
CVE-2019-17659HIGH8.1A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attack...
CVE-2019-15690HIGH8.8LibVNCServer 0.9.12 release and earlier contains heap buffer overflow vulnerability within the HandleCursorShape() funct...
CVE-2019-2483HIGH8.2Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions th...
CVE-2019-25220HIGH7.5Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-diffic...
CVE-2019-20460HIGH8.8An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tok...
CVE-2019-20459HIGH8.4An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all value...
CVE-2019-20458HIGH8.8An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions...
CVE-2019-25219HIGH7.5Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error inf...
CVE-2019-25215HIGH7.3The ARI-Adminer plugin for WordPress is vulnerable to authorization bypass due to a lack of file access controls in near...
CVE-2019-25213HIGH7.5The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to,...
CVE-2019-6198HIGH7.8A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc...
CVE-2019-6197HIGH7.8A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to esc...
CVE-2019-16641HIGH8.4An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attac...
CVE-2019-16640HIGH7.5An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mis...
CVE-2019-16638HIGH7.5An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data...
CVE-2019-6268HIGH7.5RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Direc...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now