2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19897 | CRITICAL | 9.8 | 5.6% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can comm... |
| CVE-2019-19896 | CRITICAL | 9.9 | 3.0% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The defau... |
| CVE-2019-19895 | HIGH | 7.8 | 0.4% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system... |
| CVE-2019-19894 | MEDIUM | 5.5 | 0.3% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. A... |
| CVE-2019-19893 | HIGH | 7.5 | 2.5% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated... |
| CVE-2019-16517 | CRITICAL | 9.8 | 1.3% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS miscon... |
| CVE-2019-16516 | MEDIUM | 5.3 | 19.1% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a user enumer... |
| CVE-2019-16515 | MEDIUM | 6.5 | 1.7% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security ... |
| CVE-2019-16514 | HIGH | 7.2 | 4.2% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remo... |
| CVE-2019-16513 | HIGH | 8.8 | 1.0% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to se... |
| CVE-2019-16512 | MEDIUM | 4.8 | 1.2% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is stored XSS in... |
| CVE-2019-15712 | HIGH | 7.2 | 1.0% | Jan 23, 2020 | An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow admi... |
| CVE-2019-15707 | MEDIUM | 4.9 | 1.2% | Jan 23, 2020 | An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow admi... |
| CVE-2019-5593 | MEDIUM | 5.5 | 0.2% | Jan 23, 2020 | Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plai... |
| CVE-2019-18222 | MEDIUM | 4.7 | 0.3% | Jan 23, 2020 | The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the bli... |
| CVE-2019-16153 | CRITICAL | 9.8 | 1.1% | Jan 23, 2020 | A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attac... |
| CVE-2019-14888 | HIGH | 7.5 | 2.1% | Jan 23, 2020 | A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker... |
| CVE-2019-3691 | HIGH | 7.8 | 0.5% | Jan 23, 2020 | A Symbolic Link (Symlink) Following vulnerability in the packaging of munge in SUSE Linux Enterprise Server 15; openSUSE... |
| CVE-2019-19839 | CRITICAL | 9.8 | 3.3% | Jan 23, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19838 | CRITICAL | 9.8 | 24.4% | Jan 23, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-18899 | MEDIUM | 5.5 | 0.3% | Jan 23, 2020 | The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root pri... |
| CVE-2019-17202 | HIGH | 7.8 | 0.3% | Jan 23, 2020 | FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el... |
| CVE-2019-17201 | HIGH | 7.8 | 0.3% | Jan 23, 2020 | FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to el... |
| CVE-2019-18898 | HIGH | 7.8 | 0.5% | Jan 23, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE Linux Enterprise Server 15 SP1; ope... |
| CVE-2019-19837 | MEDIUM | 5.3 | 2.0% | Jan 23, 2020 | Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote informa... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now