2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14887 | CRITICAL | 9.1 | 1.1% | Mar 16, 2020 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly co... |
| CVE-2019-14512 | MEDIUM | 6.1 | 1.0% | Mar 16, 2020 | LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in ap... |
| CVE-2019-10091 | HIGH | 7.4 | 1.4% | Mar 16, 2020 | When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verific... |
| CVE-2019-6696 | MEDIUM | 6.1 | 0.7% | Mar 15, 2020 | An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may al... |
| CVE-2019-17654 | HIGH | 8.8 | 0.5% | Mar 15, 2020 | An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow ... |
| CVE-2019-15708 | MEDIUM | 6.7 | 0.6% | Mar 15, 2020 | A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and ... |
| CVE-2019-9474 | HIGH | 7.5 | 0.8% | Mar 15, 2020 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio... |
| CVE-2019-9473 | HIGH | 7.5 | 0.8% | Mar 15, 2020 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio... |
| CVE-2019-2216 | HIGH | 7.3 | 0.2% | Mar 15, 2020 | In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a... |
| CVE-2019-2089 | HIGH | 7.8 | 0.2% | Mar 15, 2020 | In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could l... |
| CVE-2019-2088 | MEDIUM | 5.5 | 0.1% | Mar 15, 2020 | In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were n... |
| CVE-2019-2058 | MEDIUM | 6.5 | 0.7% | Mar 15, 2020 | In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no addition... |
| CVE-2019-15608 | MEDIUM | 5.9 | 1.8% | Mar 15, 2020 | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writ... |
| CVE-2019-3770 | MEDIUM | 6.4 | 0.7% | Mar 13, 2020 | Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregisterin... |
| CVE-2019-3769 | MEDIUM | 6.4 | 0.7% | Mar 13, 2020 | Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authent... |
| CVE-2019-18578 | CRITICAL | 9 | 1.1% | Mar 13, 2020 | Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malic... |
| CVE-2019-18577 | MEDIUM | 6.7 | 0.3% | Mar 13, 2020 | Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local... |
| CVE-2019-18576 | MEDIUM | 6.7 | 0.3% | Mar 13, 2020 | Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords a... |
| CVE-2019-19611 | HIGH | 7.5 | 1.1% | Mar 13, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to a... |
| CVE-2019-14310 | CRITICAL | 9.8 | 1.9% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3). Unauthenticated crafted packets to the IPP service ... |
| CVE-2019-14309 | HIGH | 7.5 | 1.2% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer... |
| CVE-2019-14303 | HIGH | 7.5 | 1.3% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD se... |
| CVE-2019-14299 | CRITICAL | 9.8 | 1.4% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices have an Authentication Method Vulnerable to Brute Force Attacks. Some Ricoh printers did no... |
| CVE-2019-13202 | CRITICAL | 9.8 | 2.7% | Mar 13, 2020 | Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in... |
| CVE-2019-13201 | CRITICAL | 9.8 | 2.7% | Mar 13, 2020 | Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now