2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16313 | HIGH | 7.5 | 47.0% | Sep 14, 2019 | ifw8 Router ROM v4.31 allows credential disclosure by reading the action/usermanager.htm HTML source code. |
| CVE-2019-16311 | HIGH | 8.8 | 0.6% | Sep 14, 2019 | NIUSHOP V1.11 has CSRF via search_info to index.php. |
| CVE-2019-16294 | HIGH | 7.8 | 9.8% | Sep 14, 2019 | SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch... |
| CVE-2019-16305 | HIGH | 8.8 | 6.7% | Sep 14, 2019 | In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup ... |
| CVE-2019-5484 | HIGH | 7.5 | 2.6% | Sep 13, 2019 | Bower before 1.8.8 has a path traversal vulnerability permitting file write in arbitrary locations via install command, ... |
| CVE-2019-11660 | HIGH | 7.8 | 7.8% | Sep 13, 2019 | Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30, ... |
| CVE-2019-5315 | HIGH | 7.2 | 2.2% | Sep 13, 2019 | A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated us... |
| CVE-2019-16293 | HIGH | 8.8 | 1.6% | Sep 13, 2019 | The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS comma... |
| CVE-2019-13532 | HIGH | 7.5 | 3.2% | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque... |
| CVE-2019-10937 | HIGH | 7.5 | 1.5% | Sep 13, 2019 | A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to th... |
| CVE-2019-16288 | HIGH | 7.5 | 1.4% | Sep 13, 2019 | On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the devi... |
| CVE-2019-12516 | HIGH | 8.8 | 2.3% | Sep 13, 2019 | The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad... |
| CVE-2019-16277 | HIGH | 7.8 | 0.9% | Sep 13, 2019 | PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionC... |
| CVE-2019-13534 | HIGH | 7.2 | 0.7% | Sep 12, 2019 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ... |
| CVE-2019-13530 | HIGH | 7.2 | 1.4% | Sep 12, 2019 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ... |
| CVE-2019-8076 | HIGH | 7.8 | 4.1% | Sep 12, 2019 | Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Success... |
| CVE-2019-11899 | HIGH | 7.5 | 1.1% | Sep 12, 2019 | An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a cl... |
| CVE-2019-11774 | HIGH | 7.4 | 0.7% | Sep 12, 2019 | Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pul... |
| CVE-2019-11773 | HIGH | 7.8 | 0.4% | Sep 12, 2019 | Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevatio... |
| CVE-2019-6007 | HIGH | 8.8 | 2.0% | Sep 12, 2019 | Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) con... |
| CVE-2019-5996 | HIGH | 8.8 | 1.5% | Sep 12, 2019 | SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execut... |
| CVE-2019-5993 | HIGH | 8.8 | 0.8% | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allo... |
| CVE-2019-5992 | HIGH | 8.8 | 0.9% | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r... |
| CVE-2019-5991 | HIGH | 7.6 | 1.2% | Sep 12, 2019 | SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitr... |
| CVE-2019-5986 | HIGH | 8.8 | 0.8% | Sep 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay pr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now