2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19607 | CRITICAL | 9.8 | 1.7% | Mar 2, 2020 | A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unau... |
| CVE-2019-19371 | MEDIUM | 6.1 | 1.0% | Mar 2, 2020 | A cross-site scripting (XSS) vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could ... |
| CVE-2019-19370 | MEDIUM | 6.1 | 1.0% | Mar 2, 2020 | A cross-site scripting (XSS) vulnerability in the web conferencing component of the Mitel MiCollab application before 9.... |
| CVE-2019-18863 | MEDIUM | 5.9 | 0.5% | Mar 2, 2020 | A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versi... |
| CVE-2019-18903 | CRITICAL | 9.8 | 2.4% | Mar 2, 2020 | A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L... |
| CVE-2019-18902 | CRITICAL | 9.8 | 2.4% | Mar 2, 2020 | A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L... |
| CVE-2019-14892 | CRITICAL | 9.8 | 5.4% | Mar 2, 2020 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymor... |
| CVE-2019-20489 | CRITICAL | 9.8 | 1.3% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentic... |
| CVE-2019-20488 | CRITICAL | 9.8 | 2.1% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (set... |
| CVE-2019-20487 | HIGH | 8.8 | 0.5% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the WNR1000V4 web management cons... |
| CVE-2019-20486 | MEDIUM | 6.1 | 0.7% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple pages (setup.cgi and adv_index.htm) within the w... |
| CVE-2019-18901 | MEDIUM | 5.5 | 0.4% | Mar 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linu... |
| CVE-2019-18897 | HIGH | 7.8 | 0.4% | Mar 2, 2020 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE... |
| CVE-2019-12183 | HIGH | 7.5 | 2.1% | Mar 2, 2020 | Incorrect Access Control in Safescan Timemoto TM-616 and TA-8000 series allows remote attackers to read any file via the... |
| CVE-2019-17026 | HIGH | 8.8 | 46.6% | Mar 2, 2020 | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are ... |
| CVE-2019-7007 | HIGH | 8.6 | 1.7% | Feb 28, 2020 | A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. ... |
| CVE-2019-4301 | HIGH | 8.4 | 1.2% | Feb 28, 2020 | BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Runnin... |
| CVE-2019-10805 | HIGH | 7.5 | 1.4% | Feb 28, 2020 | valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspe... |
| CVE-2019-10804 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is... |
| CVE-2019-10803 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" i... |
| CVE-2019-10802 | CRITICAL | 9.8 | 2.4% | Feb 28, 2020 | giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is ... |
| CVE-2019-10801 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" functi... |
| CVE-2019-19943 | HIGH | 7.5 | 4.3% | Feb 28, 2020 | The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corru... |
| CVE-2019-15609 | CRITICAL | 9.8 | 3.9% | Feb 28, 2020 | The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. |
| CVE-2019-10064 | HIGH | 7.5 | 3.7% | Feb 28, 2020 | hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now