2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12957 | HIGH | 7.8 | 1.2% | Jun 25, 2019 | In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the inde... |
| CVE-2019-7229 | HIGH | 8.3 | 1.1% | Jun 24, 2019 | The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilizat... |
| CVE-2019-7232 | HIGH | 8.8 | 52.1% | Jun 24, 2019 | The ABB IDAL HTTP server is vulnerable to a buffer overflow when a long Host header is sent in a web request. The Host h... |
| CVE-2019-7230 | HIGH | 8.8 | 3.7% | Jun 24, 2019 | The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authent... |
| CVE-2019-12936 | HIGH | 7.1 | 3.5% | Jun 23, 2019 | BlueStacks App Player 2, 3, and 4 before 4.90 allows DNS Rebinding for attacks on exposed IPC functions. |
| CVE-2019-12935 | HIGH | 7.4 | 2.7% | Jun 23, 2019 | Shopware before 5.5.8 has XSS via the Query String to the backend/Login or backend/Login/load/ URI. |
| CVE-2019-10720 | HIGH | 8.8 | 7.1% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File... |
| CVE-2019-10270 | HIGH | 8.8 | 1.2% | Jun 21, 2019 | An arbitrary password reset issue was discovered in the Ultimate Member plugin 2.39 for WordPress. It is possible (due t... |
| CVE-2019-1904 | HIGH | 8.8 | 1.0% | Jun 21, 2019 | A vulnerability in the web-based UI (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to... |
| CVE-2019-3735 | HIGH | 7.8 | 0.3% | Jun 20, 2019 | Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.... |
| CVE-2019-1878 | HIGH | 7.5 | 1.1% | Jun 20, 2019 | A vulnerability in the Cisco Discovery Protocol (CDP) implementation for the Cisco TelePresence Codec (TC) and Collabora... |
| CVE-2019-1874 | HIGH | 8.8 | 0.8% | Jun 20, 2019 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog Software could allow an unauthentic... |
| CVE-2019-1869 | HIGH | 8.6 | 2.6% | Jun 20, 2019 | A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual ... |
| CVE-2019-1843 | HIGH | 8.6 | 2.2% | Jun 20, 2019 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless... |
| CVE-2019-1626 | HIGH | 8.8 | 1.9% | Jun 20, 2019 | A vulnerability in the vManage web-based UI (Web UI) of the Cisco SD-WAN Solution could allow an authenticated, remote a... |
| CVE-2019-1625 | HIGH | 7.8 | 0.4% | Jun 20, 2019 | A vulnerability in the CLI of Cisco SD-WAN Solution could allow an authenticated, local attacker to elevate lower-level ... |
| CVE-2019-1624 | HIGH | 8.8 | 4.3% | Jun 20, 2019 | A vulnerability in the vManage web-based UI (Web UI) in the Cisco SD-WAN Solution could allow an authenticated, remote a... |
| CVE-2019-3787 | HIGH | 8.3 | 1.1% | Jun 19, 2019 | Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is... |
| CVE-2019-3737 | HIGH | 7.5 | 1.8% | Jun 19, 2019 | Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious us... |
| CVE-2019-4364 | HIGH | 8 | 2.6% | Jun 19, 2019 | IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote authenticated attacker to exe... |
| CVE-2019-3896 | HIGH | 7 | 0.4% | Jun 19, 2019 | A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker... |
| CVE-2019-11479 | HIGH | 7.5 | 91.7% | Jun 19, 2019 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fra... |
| CVE-2019-11477 | HIGH | 7.5 | 98.7% | Jun 19, 2019 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux ... |
| CVE-2019-11271 | HIGH | 7.8 | 0.3% | Jun 19, 2019 | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials w... |
| CVE-2019-12881 | HIGH | 7.8 | 0.8% | Jun 18, 2019 | i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_userptr.c in the Linux kernel 4.15.0 on Ubuntu 18.04.2 allow... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now