2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5138 | CRITICAL | 9.9 | 5.4% | Feb 25, 2020 | An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A... |
| CVE-2019-5137 | HIGH | 7.5 | 2.3% | Feb 25, 2020 | The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic ... |
| CVE-2019-5136 | HIGH | 8.8 | 2.5% | Feb 25, 2020 | An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware ... |
| CVE-2019-4672 | MEDIUM | 5.3 | 1.4% | Feb 25, 2020 | IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially c... |
| CVE-2019-4557 | HIGH | 7.5 | 0.8% | Feb 25, 2020 | IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an at... |
| CVE-2019-17569 | MEDIUM | 4.8 | 8.9% | Feb 24, 2020 | The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression... |
| CVE-2019-17229 | MEDIUM | 6.1 | 1.4% | Feb 24, 2020 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ... |
| CVE-2019-17228 | MEDIUM | 6.5 | 1.2% | Feb 24, 2020 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ... |
| CVE-2019-12513 | MEDIUM | 6.1 | 0.8% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname fiel... |
| CVE-2019-12512 | MEDIUM | 6.1 | 0.9% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by suppl... |
| CVE-2019-12511 | CRITICAL | 9.8 | 2.3% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a... |
| CVE-2019-12510 | CRITICAL | 9.1 | 0.7% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGE... |
| CVE-2019-10799 | HIGH | 8.2 | 2.2% | Feb 24, 2020 | compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "d... |
| CVE-2019-10798 | MEDIUM | 5.3 | 1.0% | Feb 24, 2020 | rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.pro... |
| CVE-2019-10796 | CRITICAL | 9.8 | 2.7% | Feb 24, 2020 | rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.j... |
| CVE-2019-4745 | MEDIUM | 4.3 | 0.9% | Feb 24, 2020 | IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated ... |
| CVE-2019-4703 | MEDIUM | 5.3 | 0.5% | Feb 24, 2020 | IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacke... |
| CVE-2019-4595 | MEDIUM | 6.1 | 0.7% | Feb 24, 2020 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing a... |
| CVE-2019-20481 | CRITICAL | 9.8 | 0.6% | Feb 24, 2020 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old passwo... |
| CVE-2019-20480 | HIGH | 8.8 | 0.4% | Feb 24, 2020 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious... |
| CVE-2019-18183 | CRITICAL | 9.8 | 3.7% | Feb 24, 2020 | pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. Thi... |
| CVE-2019-18182 | CRITICAL | 9.8 | 3.7% | Feb 24, 2020 | pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. Th... |
| CVE-2019-20044 | HIGH | 7.8 | 0.5% | Feb 24, 2020 | In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh f... |
| CVE-2019-15299 | HIGH | 8.8 | 1.6% | Feb 24, 2020 | An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the conta... |
| CVE-2019-3670 | MEDIUM | 6.1 | 1.2% | Feb 24, 2020 | Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now