2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18943 | HIGH | 8 | 0.3% | Feb 26, 2021 | Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) o... |
| CVE-2019-19005 | HIGH | 7.8 | 1.0% | Feb 11, 2021 | A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitma... |
| CVE-2019-25018 | HIGH | 7.5 | 1.6% | Feb 2, 2021 | In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the fi... |
| CVE-2019-20471 | HIGH | 7.8 | 0.4% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup,... |
| CVE-2019-20470 | HIGH | 7.5 | 1.9% | Feb 1, 2021 | An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SM... |
| CVE-2019-25016 | HIGH | 8.8 | 2.6% | Jan 28, 2021 | In OpenDoas from 6.6 to 6.8 the users PATH variable was incorrectly inherited by authenticated executions if the authent... |
| CVE-2019-4702 | HIGH | 8.1 | 0.4% | Jan 13, 2021 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 specifies permissions for a security-critical resource in a way that... |
| CVE-2019-4160 | HIGH | 7.5 | 0.6% | Jan 13, 2021 | IBM Security Guardium Data Encryption (GDE) 3.0.0.2 uses weaker than expected cryptographic algorithms that could allow ... |
| CVE-2019-20484 | HIGH | 8.1 | 0.9% | Jan 5, 2021 | An issue was discovered in Viki Vera 4.9.1.26180. A user without access to a project could download or upload project fi... |
| CVE-2019-4728 | HIGH | 8.8 | 5.0% | Jan 5, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow... |
| CVE-2019-25012 | HIGH | 7.5 | 1.4% | Jan 1, 2021 | The Webform Report project 7.x-1.x-dev for Drupal allows remote attackers to view submissions by visiting the /rss.xml p... |
| CVE-2019-25007 | HIGH | 7.5 | 1.3% | Dec 31, 2020 | An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can cause a panic. |
| CVE-2019-25006 | HIGH | 7.5 | 0.8% | Dec 31, 2020 | An issue was discovered in the streebog crate before 0.8.0 for Rust. The Streebog hash function can produce the wrong an... |
| CVE-2019-25005 | HIGH | 7.5 | 1.3% | Dec 31, 2020 | An issue was discovered in the chacha20 crate before 0.2.3 for Rust. A ChaCha20 counter overflow makes it easier for att... |
| CVE-2019-25003 | HIGH | 7.5 | 1.4% | Dec 31, 2020 | An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-cha... |
| CVE-2019-25001 | HIGH | 7.5 | 1.4% | Dec 31, 2020 | An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio... |
| CVE-2019-16747 | HIGH | 7.5 | 1.8% | Dec 30, 2020 | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and ... |
| CVE-2019-16281 | HIGH | 7.5 | 1.3% | Dec 30, 2020 | Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code ... |
| CVE-2019-15080 | HIGH | 7.5 | 1.6% | Dec 30, 2020 | An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo... |
| CVE-2019-15079 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This ... |
| CVE-2019-15078 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The ... |
| CVE-2019-11781 | HIGH | 8.8 | 2.1% | Dec 22, 2020 | Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, a... |
| CVE-2019-14479 | HIGH | 8.8 | 4.0% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can exe... |
| CVE-2019-14483 | HIGH | 8.8 | 1.8% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 allows Credentials Disclosure. Every user can read the BSD, Linux, MacOS and Solaris private... |
| CVE-2019-19289 | HIGH | 8.8 | 0.4% | Dec 14, 2020 | A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow a Cross-Site Request Forg... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now