2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16065 | HIGH | 8.8 | 2.8% | Mar 19, 2020 | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a... |
| CVE-2019-16064 | CRITICAL | 9.6 | 1.3% | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user... |
| CVE-2019-16062 | MEDIUM | 6.5 | 0.8% | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an... |
| CVE-2019-16061 | HIGH | 8.8 | 1.0% | Mar 19, 2020 | A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable pe... |
| CVE-2019-15656 | HIGH | 7.5 | 1.3% | Mar 19, 2020 | D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques... |
| CVE-2019-15655 | HIGH | 7.5 | 1.4% | Mar 19, 2020 | D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to ... |
| CVE-2019-15654 | HIGH | 7.5 | 1.5% | Mar 19, 2020 | Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download... |
| CVE-2019-15653 | HIGH | 7.5 | 0.8% | Mar 19, 2020 | Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism.... |
| CVE-2019-12127 | CRITICAL | 9.8 | 1.2% | Mar 19, 2020 | In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and... |
| CVE-2019-12126 | CRITICAL | 9.8 | 1.2% | Mar 19, 2020 | In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, an... |
| CVE-2019-12125 | CRITICAL | 9.8 | 1.2% | Mar 19, 2020 | In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285,... |
| CVE-2019-16382 | CRITICAL | 9.8 | 2.9% | Mar 19, 2020 | An issue was discovered in Ivanti Workspace Control 10.3.110.0. One is able to bypass Ivanti's FileGuard folder protecti... |
| CVE-2019-11361 | HIGH | 8.8 | 3.0% | Mar 19, 2020 | Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala... |
| CVE-2019-16012 | HIGH | 8.1 | 54.2% | Mar 19, 2020 | A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to... |
| CVE-2019-16010 | MEDIUM | 4.8 | 0.8% | Mar 19, 2020 | A vulnerability in the web UI of the Cisco SD-WAN vManage software could allow an authenticated, remote attacker to cond... |
| CVE-2019-14878 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-14877 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc... |
| CVE-2019-14876 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Ballo... |
| CVE-2019-14875 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Bal... |
| CVE-2019-14874 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-14873 | MEDIUM | 6.5 | 1.3% | Mar 19, 2020 | In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc i... |
| CVE-2019-5104 | — | — | — | Mar 19, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-9013. Reason: This candidate is a duplicate of C... |
| CVE-2019-12416 | MEDIUM | 6.1 | 2.6% | Mar 19, 2020 | we got reports for 2 injection attacks against the DeltaSpike windowhandler.js. This is only active if a developer selec... |
| CVE-2019-20527 | MEDIUM | 6.1 | 0.9% | Mar 19, 2020 | Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. |
| CVE-2019-20524 | MEDIUM | 6.1 | 0.7% | Mar 19, 2020 | ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now