2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16659 | HIGH | 8.8 | 0.5% | Sep 21, 2019 | TuziCMS 2.0.6 has index.php/manage/link/do_add CSRF. |
| CVE-2019-16658 | HIGH | 8.8 | 0.5% | Sep 21, 2019 | TuziCMS 2.0.6 has index.php/manage/notice/do_add CSRF. |
| CVE-2019-16655 | HIGH | 7.5 | 0.8% | Sep 21, 2019 | joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available. |
| CVE-2019-15138 | HIGH | 7.5 | 1.9% | Sep 20, 2019 | The html-pdf package 2.2.0 for Node.js has an arbitrary file read vulnerability via an HTML file that uses XMLHttpReques... |
| CVE-2019-16645 | HIGH | 8.6 | 8.2% | Sep 20, 2019 | An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre... |
| CVE-2019-14816 | HIGH | 7.8 | 0.9% | Sep 20, 2019 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Lin... |
| CVE-2019-14814 | HIGH | 7.8 | 0.9% | Sep 20, 2019 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver ... |
| CVE-2019-11326 | HIGH | 8.8 | 1.2% | Sep 20, 2019 | An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the... |
| CVE-2019-11280 | HIGH | 8.8 | 1.5% | Sep 20, 2019 | Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.18, 2.4.x prior to 2.4.14, 2.5... |
| CVE-2019-4565 | HIGH | 7.5 | 1.5% | Sep 20, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, wh... |
| CVE-2019-15089 | HIGH | 8.8 | 0.6% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a... |
| CVE-2019-15087 | HIGH | 7.2 | 3.3% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any... |
| CVE-2019-15085 | HIGH | 7.5 | 1.4% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. |
| CVE-2019-16531 | HIGH | 8.8 | 2.5% | Sep 20, 2019 | LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. |
| CVE-2019-9719 | HIGH | 8.8 | 2.0% | Sep 19, 2019 | A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ... |
| CVE-2019-14821 | HIGH | 8.8 | 0.8% | Sep 19, 2019 | An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hyp... |
| CVE-2019-15033 | HIGH | 7.7 | 1.3% | Sep 19, 2019 | Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address... |
| CVE-2019-16510 | HIGH | 7.5 | 1.4% | Sep 19, 2019 | libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrate... |
| CVE-2019-16412 | HIGH | 7.5 | 1.4% | Sep 19, 2019 | In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Pro... |
| CVE-2019-15001 | HIGH | 7.2 | 11.4% | Sep 19, 2019 | The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 bef... |
| CVE-2019-14994 | HIGH | 7.5 | 5.1% | Sep 19, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before version 3.9.1... |
| CVE-2019-6010 | HIGH | 7.8 | 1.7% | Sep 19, 2019 | Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause... |
| CVE-2019-15943 | HIGH | 8.8 | 8.7% | Sep 19, 2019 | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de... |
| CVE-2019-16413 | HIGH | 7.5 | 2.9% | Sep 19, 2019 | An issue was discovered in the Linux kernel before 5.0.4. The 9p filesystem did not protect i_size_write() properly, whi... |
| CVE-2019-13556 | HIGH | 8.8 | 2.1% | Sep 18, 2019 | In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of prop... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now