2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20478 | CRITICAL | 9.8 | 6.6% | Feb 19, 2020 | In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an... |
| CVE-2019-20477 | CRITICAL | 9.8 | 5.0% | Feb 19, 2020 | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserializa... |
| CVE-2019-10791 | CRITICAL | 9.8 | 2.0% | Feb 18, 2020 | promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and opti... |
| CVE-2019-5613 | CRITICAL | 9.8 | 0.6% | Feb 18, 2020 | In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an ... |
| CVE-2019-18352 | HIGH | 8.2 | 0.4% | Feb 18, 2020 | Improper access control exists on PHOENIX CONTACT FL NAT 2208 devices before V2.90 and FL NAT 2304-2GC-2SFP devices befo... |
| CVE-2019-15875 | LOW | 3.3 | 0.3% | Feb 18, 2020 | In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-S... |
| CVE-2019-10795 | MEDIUM | 6.3 | 1.1% | Feb 18, 2020 | undefsafe before 2.0.3 is vulnerable to Prototype Pollution. The 'a' function could be tricked into adding or modifying ... |
| CVE-2019-10794 | MEDIUM | 6.3 | 0.7% | Feb 18, 2020 | All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or ... |
| CVE-2019-10793 | MEDIUM | 6.3 | 1.1% | Feb 18, 2020 | dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying... |
| CVE-2019-10792 | MEDIUM | 6.3 | 1.0% | Feb 18, 2020 | bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifyin... |
| CVE-2019-19325 | MEDIUM | 6.1 | 0.7% | Feb 17, 2020 | SilverStripe through 4.4.x before 4.4.5 and 4.5.x before 4.5.2 allows Reflected XSS on the login form and custom forms. ... |
| CVE-2019-10790 | HIGH | 7.5 | 1.8% | Feb 17, 2020 | taffydb npm module, vulnerable in all versions up to and including 2.7.3, allows attackers to forge adding additional pr... |
| CVE-2019-20474 | MEDIUM | 4.3 | 1.4% | Feb 17, 2020 | An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configurat... |
| CVE-2019-18998 | HIGH | 7.1 | 0.8% | Feb 17, 2020 | Insufficient access control in the web interface of ABB Asset Suite versions 9.0 to 9.3, 9.4 prior to 9.4.2.6, 9.5 prior... |
| CVE-2019-12954 | MEDIUM | 5.4 | 1.4% | Feb 17, 2020 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users ... |
| CVE-2019-12825 | MEDIUM | 4.3 | 1.1% | Feb 17, 2020 | Unauthorized Access to the Container Registry of other groups was discovered in GitLab Enterprise 12.0.0-pre. In other w... |
| CVE-2019-20456 | HIGH | 7.8 | 0.7% | Feb 16, 2020 | Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an ... |
| CVE-2019-5187 | HIGH | 8.8 | 3.6% | Feb 14, 2020 | An exploitable out-of-bounds write vulnerability exists in the TIFreadstripdata function of the igcore19d.dll library of... |
| CVE-2019-4392 | CRITICAL | 9.8 | 1.4% | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get... |
| CVE-2019-15594 | MEDIUM | 4.3 | 0.8% | Feb 14, 2020 | GitLab 11.8 and later contains a security vulnerability that allows a user to obtain details of restricted pipelines via... |
| CVE-2019-15592 | MEDIUM | 4.3 | 1.0% | Feb 14, 2020 | GitLab 12.2.2 and below contains a security vulnerability that allows a guest user in a private project to see the merge... |
| CVE-2019-13967 | HIGH | 7.5 | 1.3% | Feb 14, 2020 | iTop 2.2.0 through 2.6.0 allows remote attackers to cause a denial of service (application outage) via many requests to ... |
| CVE-2019-13966 | MEDIUM | 6.1 | 0.8% | Feb 14, 2020 | In iTop through 2.6.0, an XSS payload can be delivered in certain fields (such as icon) of the XML file used to build th... |
| CVE-2019-13965 | MEDIUM | 6.1 | 1.6% | Feb 14, 2020 | Because of a lack of sanitization around error messages, multiple Reflective XSS issues exist in iTop through 2.6.0 via ... |
| CVE-2019-11215 | HIGH | 8.1 | 1.2% | Feb 14, 2020 | In Combodo iTop 2.2.0 through 2.6.0, if the configuration file is writable, then execution of arbitrary code can be acco... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now