2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16701 | HIGH | 8.8 | 19.6% | Sep 25, 2019 | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph... |
| CVE-2019-10428 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the ... |
| CVE-2019-10412 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenki... |
| CVE-2019-10411 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the globa... |
| CVE-2019-5094 | HIGH | 7.5 | 1.1% | Sep 24, 2019 | An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially craf... |
| CVE-2019-13527 | HIGH | 7.8 | 5.3% | Sep 24, 2019 | In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Aren... |
| CVE-2019-16754 | HIGH | 7.5 | 1.5% | Sep 24, 2019 | RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attac... |
| CVE-2019-14753 | HIGH | 7.5 | 1.2% | Sep 24, 2019 | SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow |
| CVE-2019-13357 | HIGH | 7.8 | 0.6% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allo... |
| CVE-2019-13356 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-13355 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-16729 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all... |
| CVE-2019-10754 | HIGH | 8.1 | 1.8% | Sep 23, 2019 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for... |
| CVE-2019-1367 | HIGH | 7.5 | 52.7% | Sep 23, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-1255 | HIGH | 7.5 | 3.9% | Sep 23, 2019 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denia... |
| CVE-2019-11277 | HIGH | 8.1 | 1.7% | Sep 23, 2019 | Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP ... |
| CVE-2019-10996 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10984 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10978 | HIGH | 7.8 | 0.9% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-13063 | HIGH | 7.5 | 27.2% | Sep 23, 2019 | Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc... |
| CVE-2019-16720 | HIGH | 7.5 | 1.4% | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=c... |
| CVE-2019-16718 | HIGH | 7.8 | 2.3% | Sep 23, 2019 | In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft... |
| CVE-2019-16714 | HIGH | 7.5 | 2.7% | Sep 23, 2019 | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information... |
| CVE-2019-16706 | HIGH | 8.8 | 0.6% | Sep 23, 2019 | kkcms v1.3 has a CSRF vulnerablity that can add an user account via admin/cms_user_add.php. |
| CVE-2019-16660 | HIGH | 8.8 | 0.5% | Sep 21, 2019 | joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now