2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20360 | HIGH | 7.5 | 2.5% | Jan 8, 2020 | A flaw in Give before 2.5.5, a WordPress plugin, allowed unauthenticated users to bypass API authentication methods and ... |
| CVE-2019-17151 | MEDIUM | 5.4 | 1.4% | Jan 7, 2020 | This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent W... |
| CVE-2019-17148 | HIGH | 7.8 | 0.5% | Jan 7, 2020 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel... |
| CVE-2019-17147 | HIGH | 8.8 | 13.7% | Jan 7, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N rout... |
| CVE-2019-17146 | CRITICAL | 9.8 | 9.5% | Jan 7, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.... |
| CVE-2019-18652 | MEDIUM | 6.1 | 0.8% | Jan 7, 2020 | A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to... |
| CVE-2019-6529 | MEDIUM | 4.9 | 1.0% | Jan 7, 2020 | An attacker could specially craft an FTP request that could crash the PR100088 Modbus gateway versions prior to release ... |
| CVE-2019-14906 | CRITICAL | 9.8 | 1.8% | Jan 7, 2020 | A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue ... |
| CVE-2019-9465 | MEDIUM | 5.5 | 0.3% | Jan 7, 2020 | In the Titan M handling of cryptographic operations, there is a possible information disclosure due to an unusual root c... |
| CVE-2019-6700 | MEDIUM | 6.5 | 0.9% | Jan 7, 2020 | An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may all... |
| CVE-2019-18386 | HIGH | 8.7 | 0.8% | Jan 7, 2020 | Systems management on Unisys ClearPath Forward Libra and ClearPath MCP Software Series can fault and have other unspecif... |
| CVE-2019-16154 | MEDIUM | 6.1 | 0.7% | Jan 7, 2020 | An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthent... |
| CVE-2019-10776 | CRITICAL | 9.8 | 2.1% | Jan 7, 2020 | In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. ... |
| CVE-2019-14819 | HIGH | 8.8 | 1.0% | Jan 7, 2020 | A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc s... |
| CVE-2019-14879 | MEDIUM | 5.4 | 0.7% | Jan 7, 2020 | A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohor... |
| CVE-2019-14866 | HIGH | 7.3 | 0.7% | Jan 7, 2020 | In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is us... |
| CVE-2019-14854 | MEDIUM | 6.5 | 0.8% | Jan 7, 2020 | OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given op... |
| CVE-2019-14843 | HIGH | 8.8 | 1.2% | Jan 7, 2020 | A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. Thi... |
| CVE-2019-14837 | CRITICAL | 9.1 | 1.7% | Jan 7, 2020 | A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this ... |
| CVE-2019-14834 | LOW | 3.7 | 2.7% | Jan 7, 2020 | A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denia... |
| CVE-2019-6857 | HIGH | 7.5 | 1.6% | Jan 6, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi... |
| CVE-2019-6856 | HIGH | 7.5 | 1.6% | Jan 6, 2020 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Modicon M580, Modicon M340, Modi... |
| CVE-2019-6855 | HIGH | 7.3 | 1.0% | Jan 6, 2020 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity P... |
| CVE-2019-6854 | HIGH | 7.8 | 0.2% | Jan 6, 2020 | A CWE-287: Improper Authentication vulnerability exists in a folder within EcoStruxure Geo SCADA Expert (ClearSCADA) -wi... |
| CVE-2019-20348 | MEDIUM | 6.8 | 0.6% | Jan 6, 2020 | OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now