2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7838 | — | — | 17.4% | Jun 12, 2019 | ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blackli... |
| CVE-2019-10971 | — | — | 1.1% | Jun 12, 2019 | The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrust... |
| CVE-2019-9676 | — | — | 0.4% | Jun 12, 2019 | Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 201... |
| CVE-2019-3947 | — | — | 1.6% | Jun 12, 2019 | Fuji Electric V-Server before 6.0.33.0 stores database credentials in project files as plaintext. An attacker that can g... |
| CVE-2019-3946 | — | — | 2.3% | Jun 12, 2019 | Fuji Electric V-Server before 6.0.33.0 is vulnerable to denial of service via a crafted UDP message sent to port 8005. A... |
| CVE-2019-0308 | — | — | 0.9% | Jun 12, 2019 | An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, ca... |
| CVE-2019-0307 | — | — | 2.1% | Jun 12, 2019 | Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as So... |
| CVE-2019-0306 | — | — | 0.9% | Jun 12, 2019 | SAP HANA Extended Application Services (advanced model), version 1, allows authenticated low privileged XS Advanced Plat... |
| CVE-2019-0305 | — | — | 0.9% | Jun 12, 2019 | Java Server Pages (JSPs) provided by the SAP NetWeaver Process Integration (SAP_XIESR and SAP_XITOOL: 7.10 to 7.11, 7.20... |
| CVE-2019-0304 | — | — | 1.6% | Jun 12, 2019 | FTP Function of SAP NetWeaver AS ABAP Platform, versions- KRNL32NUC 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL32UC 7.21, 7.21EXT... |
| CVE-2019-10926 | — | — | 1.5% | Jun 12, 2019 | A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is no... |
| CVE-2019-1036 | — | — | 1.7% | Jun 12, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-1034 | — | — | 4.9% | Jun 12, 2019 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo... |
| CVE-2019-1033 | — | — | 1.7% | Jun 12, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-1032 | — | — | 1.7% | Jun 12, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-1031 | — | — | 1.7% | Jun 12, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-1029 | — | — | 5.3% | Jun 12, 2019 | A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability... |
| CVE-2019-0996 | — | — | 1.6% | Jun 12, 2019 | A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, re... |
| CVE-2019-0943 | — | — | 2.4% | Jun 12, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A... |
| CVE-2019-12795 | — | — | 0.4% | Jun 11, 2019 | daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a priv... |
| CVE-2019-12149 | — | — | 1.4% | Jun 11, 2019 | SQL injection vulnerability in silverstripe/restfulserver module 1.0.x before 1.0.9, 2.0.x before 2.0.4, and 2.1.x befor... |
| CVE-2019-0196 | — | — | 19.3% | Jun 11, 2019 | A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handlin... |
| CVE-2019-12154 | — | — | 2.3% | Jun 11, 2019 | XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML conte... |
| CVE-2019-12153 | — | — | 1.7% | Jun 11, 2019 | Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to a... |
| CVE-2019-12146 | — | — | 4.0% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Att... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now