2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19897CRITICAL9.8In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can comm...
CVE-2019-19896CRITICAL9.9In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The defau...
CVE-2019-19895HIGH7.8In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system...
CVE-2019-19894MEDIUM5.5In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. A...
CVE-2019-19893HIGH7.5In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated...
CVE-2019-16517CRITICAL9.8An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS miscon...
CVE-2019-16516MEDIUM5.3An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer...
CVE-2019-16515MEDIUM6.5An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security ...
CVE-2019-16514HIGH7.2An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remo...
CVE-2019-16513HIGH8.8An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to se...
CVE-2019-16512MEDIUM4.8An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in...
CVE-2019-15712HIGH7.2An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow admi...
CVE-2019-15707MEDIUM4.9An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow admi...
CVE-2019-5593MEDIUM5.5Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plai...
CVE-2019-18222MEDIUM4.7The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the bli...
CVE-2019-16153CRITICAL9.8A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attac...
CVE-2019-14888HIGH7.5A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker...
CVE-2019-3691HIGH7.8A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE...
CVE-2019-19839CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-19838CRITICAL9.8emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ...
CVE-2019-18899MEDIUM5.5The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root pri...
CVE-2019-17202HIGH7.8FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el...
CVE-2019-17201HIGH7.8FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el...
CVE-2019-18898HIGH7.8UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; ope...
CVE-2019-19837MEDIUM5.3Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote informa...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now