2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5138CRITICAL9.9An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A...
CVE-2019-5137HIGH7.5The usage of hard-coded cryptographic keys within the ServiceAgent binary allows for the decryption of captured traffic ...
CVE-2019-5136HIGH8.8An exploitable privilege escalation vulnerability exists in the iw_console functionality of the Moxa AWK-3131A firmware ...
CVE-2019-4672MEDIUM5.3IBM QRadar Advisor 1.1 through 2.5 could allow an unauthorized attacker to obtain sensitive information from specially c...
CVE-2019-4557HIGH7.5IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an at...
CVE-2019-17569MEDIUM4.8The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression...
CVE-2019-17229MEDIUM6.1includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ...
CVE-2019-17228MEDIUM6.5includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin ...
CVE-2019-12513MEDIUM6.1In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, by sending a DHCP discover request containing a malicious hostname fiel...
CVE-2019-12512MEDIUM6.1In NETGEAR Nighthawk X10-R900 prior to 1.0.4.24, an attacker may execute stored XSS attacks against this device by suppl...
CVE-2019-12511CRITICAL9.8In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a...
CVE-2019-12510CRITICAL9.1In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGE...
CVE-2019-10799HIGH8.2compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "d...
CVE-2019-10798MEDIUM5.3rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.pro...
CVE-2019-10796CRITICAL9.8rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.j...
CVE-2019-4745MEDIUM4.3IBM Maximo Asset Management 7.6.1.0 could allow a remote attacker to disclose sensitive information to an authenticated ...
CVE-2019-4703MEDIUM5.3IBM Spectrum Protect Plus 10.1.0 and 10.5.0, when protecting Microsoft SQL or Microsoft Exchange, could allow an attacke...
CVE-2019-4595MEDIUM6.1IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 could allow a remote attacker to conduct phishing a...
CVE-2019-20481CRITICAL9.8In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old passwo...
CVE-2019-20480HIGH8.8In MIELE XGW 3000 ZigBee Gateway before 2.4.0, a malicious website visited by an authenticated admin user or a malicious...
CVE-2019-18183CRITICAL9.8pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. Thi...
CVE-2019-18182CRITICAL9.8pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. Th...
CVE-2019-20044HIGH7.8In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh f...
CVE-2019-15299HIGH8.8An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the conta...
CVE-2019-3670MEDIUM6.1Remote Code Execution vulnerability in the web interface in McAfee Web Advisor (WA) 8.0.34745 and earlier allows remote ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now