2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12789 | — | — | 0.6% | Jun 17, 2019 | An issue was discovered on Actiontec T2200H T2200H-31.128L.08 devices, as distributed by Telus. By attaching a UART adap... |
| CVE-2019-12550 | — | — | 2.7% | Jun 17, 2019 | WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded users and passwords t... |
| CVE-2019-12549 | — | — | 3.3% | Jun 17, 2019 | WAGO 852-303 before FW06, 852-1305 before FW06, and 852-1505 before FW03 devices contain hardcoded private keys for the ... |
| CVE-2019-6326 | — | — | 1.7% | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s... |
| CVE-2019-6325 | — | — | 1.0% | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s... |
| CVE-2019-6324 | — | — | 0.7% | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s... |
| CVE-2019-6323 | — | — | 1.3% | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s... |
| CVE-2019-12855 | — | — | 1.8% | Jun 16, 2019 | In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with T... |
| CVE-2019-12840 | — | — | 77.8% | Jun 15, 2019 | In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr... |
| CVE-2019-12839 | — | — | 4.8% | Jun 15, 2019 | In OrangeHRM 4.3.1 and before, there is an input validation error within admin/listMailConfiguration (txtSendmailPath pa... |
| CVE-2019-12835 | — | — | 1.6% | Jun 15, 2019 | formats/xml.cpp in Leanify 0.4.3 allows for a controlled out-of-bounds write in xml_memory_writer::write via characters ... |
| CVE-2019-12831 | — | — | 1.5% | Jun 15, 2019 | In MyBB before 1.8.21, an attacker can abuse a default behavior of MySQL on many systems (that leads to truncation of st... |
| CVE-2019-12830 | — | — | 1.0% | Jun 15, 2019 | In MyBB before 1.8.21, an attacker can exploit a parsing flaw in the Private Message / Post renderer that leads to [vide... |
| CVE-2019-12829 | — | — | 1.7% | Jun 15, 2019 | radare2 through 3.5.1 mishandles the RParse API, which allows remote attackers to cause a denial of service (application... |
| CVE-2019-12816 | — | — | 4.1% | Jun 15, 2019 | Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbit... |
| CVE-2019-9842 | — | — | 2.2% | Jun 14, 2019 | madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element wit... |
| CVE-2019-12828 | — | — | 13.3% | Jun 14, 2019 | An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and orig... |
| CVE-2019-0316 | — | — | 0.6% | Jun 14, 2019 | SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not... |
| CVE-2019-0303 | — | — | 0.8% | Jun 14, 2019 | SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appServic... |
| CVE-2019-2259 | — | — | 0.9% | Jun 14, 2019 | Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto,... |
| CVE-2019-2257 | — | — | 0.2% | Jun 14, 2019 | Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity,... |
| CVE-2019-2256 | — | — | 1.5% | Jun 14, 2019 | An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr... |
| CVE-2019-2255 | — | — | 1.5% | Jun 14, 2019 | An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr... |
| CVE-2019-12822 | — | — | 8.8% | Jun 14, 2019 | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory asserti... |
| CVE-2019-11582 | — | — | 4.9% | Jun 14, 2019 | An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now