2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17583 | HIGH | 7.5 | 1.3% | Oct 14, 2019 | idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many ... |
| CVE-2019-17511 | HIGH | 7.5 | 1.6% | Oct 14, 2019 | There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can g... |
| CVE-2019-16519 | HIGH | 7.8 | 0.3% | Oct 14, 2019 | ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u... |
| CVE-2019-9745 | HIGH | 7.8 | 0.5% | Oct 14, 2019 | CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too... |
| CVE-2019-17575 | HIGH | 7.2 | 1.4% | Oct 14, 2019 | A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an ... |
| CVE-2019-17547 | HIGH | 8.8 | 1.8% | Oct 14, 2019 | In ImageMagick before 7.0.8-62, TraceBezier in MagickCore/draw.c has a use-after-free. |
| CVE-2019-17546 | HIGH | 8.8 | 3.4% | Oct 14, 2019 | tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that... |
| CVE-2019-17543 | HIGH | 8.1 | 9.1% | Oct 14, 2019 | LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applicati... |
| CVE-2019-17541 | HIGH | 8.8 | 2.4% | Oct 14, 2019 | ImageMagick before 7.0.8-55 has a use-after-free in DestroyStringInfo in MagickCore/string.c because the error manager i... |
| CVE-2019-17540 | HIGH | 8.8 | 2.1% | Oct 14, 2019 | ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c. |
| CVE-2019-17501 | HIGH | 8.8 | 2.5% | Oct 14, 2019 | Centreon 19.04 allows attackers to execute arbitrary OS commands via the Command Line field of main.php?p=60807&type=4 (... |
| CVE-2019-17538 | HIGH | 7.5 | 11.6% | Oct 13, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=... |
| CVE-2019-17537 | HIGH | 7.5 | 1.6% | Oct 13, 2019 | Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?... |
| CVE-2019-17534 | HIGH | 8.8 | 2.4% | Oct 13, 2019 | vips_foreign_load_gif_scan_image in foreign/gifload.c in libvips before 8.8.2 tries to access a color map before a DGifG... |
| CVE-2019-17533 | HIGH | 8.2 | 1.9% | Oct 13, 2019 | Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read ... |
| CVE-2019-17532 | HIGH | 7.5 | 1.6% | Oct 12, 2019 | An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cau... |
| CVE-2019-17530 | HIGH | 7.8 | 0.5% | Oct 12, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Cor... |
| CVE-2019-17529 | HIGH | 7.8 | 0.5% | Oct 12, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspect... |
| CVE-2019-17528 | HIGH | 7.5 | 1.1% | Oct 12, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap... |
| CVE-2019-17502 | HIGH | 7.5 | 1.7% | Oct 12, 2019 | Hydra through 0.1.8 has a NULL pointer dereference and daemon crash when processing POST requests that lack a Content-Le... |
| CVE-2019-17514 | HIGH | 7.5 | 4.7% | Oct 12, 2019 | library/glob.html in the Python 2 and 3 documentation before 2016 has potentially misleading information about whether s... |
| CVE-2019-17507 | HIGH | 7.5 | 1.6% | Oct 11, 2019 | An issue was discovered on D-Link DIR-816 A1 1.06 devices. An attacker could access management pages of the router via a... |
| CVE-2019-17505 | HIGH | 7.5 | 1.7% | Oct 11, 2019 | D-Link DAP-1320 A2-V1.21 routers have some web interfaces without authentication requirements, as demonstrated by uplink... |
| CVE-2019-2215 | HIGH | 7.8 | 72.1% | Oct 11, 2019 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti... |
| CVE-2019-2186 | HIGH | 8.8 | 1.3% | Oct 11, 2019 | In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now