2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5285 | — | — | 1.7% | Jun 4, 2019 | Some Huawei S series switches have a DoS vulnerability. An unauthenticated remote attacker can send crafted packets to t... |
| CVE-2019-5283 | — | — | 0.2% | Jun 4, 2019 | There is Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions earlier than E... |
| CVE-2019-5217 | — | — | 0.3% | Jun 4, 2019 | There is an information disclosure vulnerability on Mate 9 Pro Huawei smartphones versions earlier than LON-AL00B9.0.1.1... |
| CVE-2019-5215 | — | — | 0.3% | Jun 4, 2019 | There is a man-in-the-middle (MITM) vulnerability on Huawei P30 smartphones versions before ELE-AL00 9.1.0.162(C01E160R1... |
| CVE-2019-5306 | — | — | 0.2% | Jun 4, 2019 | There is a Factory Reset Protection (FRP) bypass security vulnerability in P20 Huawei smart phones versions before Emily... |
| CVE-2019-5296 | — | — | 0.2% | Jun 4, 2019 | Mate20 Huawei smartphones versions earlier than HMA-AL00C00B175 have an out-of-bounds read vulnerability. An attacker wi... |
| CVE-2019-5281 | — | — | 0.3% | Jun 4, 2019 | There is an information leak vulnerability in some Huawei phones, versions earlier than Jackman-L21 8.2.0.155(C185R1P2).... |
| CVE-2019-5244 | — | — | 0.7% | Jun 4, 2019 | Mate 9 Pro Huawei smartphones earlier than LON-L29C 8.0.0.361(C636) versions have an information leak vulnerability due ... |
| CVE-2019-12730 | — | — | 3.0% | Jun 4, 2019 | aa_read_header in libavformat/aadec.c in FFmpeg before 3.2.14 and 4.x before 4.1.4 does not check for sscanf failure and... |
| CVE-2019-12727 | — | — | 1.5% | Jun 4, 2019 | On Ubiquiti airCam 3.1.4 devices, a Denial of Service vulnerability exists in the RTSP Service provided by the ubnt-stre... |
| CVE-2019-9839 | — | — | 1.0% | Jun 3, 2019 | VFront 0.99.5 has Reflected XSS via the admin/menu_registri.php descrizione_g parameter or the admin/sync_reg_tab.php az... |
| CVE-2019-9838 | — | — | 1.1% | Jun 3, 2019 | VFront 0.99.5 has stored XSS via the admin/sync_reg_tab.php azzera parameter, which is mishandled during admin/error_log... |
| CVE-2019-9824 | — | — | 0.5% | Jun 3, 2019 | tcp_emu in slirp/tcp_subr.c (aka slirp/src/tcp_subr.c) in QEMU 3.0.0 uses uninitialized data in an snprintf call, leadin... |
| CVE-2019-12548 | — | — | 3.0% | Jun 3, 2019 | Bludit before 3.9.0 allows remote code execution for an authenticated user by uploading a php file while changing the lo... |
| CVE-2019-12097 | — | — | 0.6% | Jun 3, 2019 | Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to co... |
| CVE-2019-11368 | — | — | 1.6% | Jun 3, 2019 | Stored XSS was discovered in AUO Solar Data Recorder before 1.3.0 via the protect/config.htm addr parameter. |
| CVE-2019-11367 | — | — | 2.8% | Jun 3, 2019 | An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provi... |
| CVE-2019-11185 | — | — | 4.3% | Jun 3, 2019 | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This r... |
| CVE-2019-10883 | — | — | 65.5% | Jun 3, 2019 | Citrix SD-WAN Center 10.2.x before 10.2.1 and NetScaler SD-WAN Center 10.0.x before 10.0.7 allow Command Injection. |
| CVE-2019-10009 | — | — | 11.5% | Jun 3, 2019 | A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated use... |
| CVE-2019-6588 | — | — | 2.3% | Jun 3, 2019 | In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsani... |
| CVE-2019-12377 | — | — | 5.5% | Jun 3, 2019 | A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.... |
| CVE-2019-12376 | — | — | 0.6% | Jun 3, 2019 | Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Up... |
| CVE-2019-12375 | — | — | 1.1% | Jun 3, 2019 | Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to... |
| CVE-2019-12374 | — | — | 2.6% | Jun 3, 2019 | A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now