2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10546 | CRITICAL | 9.8 | 0.9% | Mar 5, 2020 | Buffer overflow can occur in WLAN firmware while parsing beacon/probe_response frames during roaming in Snapdragon Auto,... |
| CVE-2019-10526 | CRITICAL | 9.8 | 0.9% | Mar 5, 2020 | Out of bound write in WLAN driver due to NULL character not properly placed after SSID name in Snapdragon Auto, Snapdrag... |
| CVE-2019-14893 | CRITICAL | 9.8 | 4.0% | Mar 2, 2020 | A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit poly... |
| CVE-2019-19608 | CRITICAL | 9.8 | 1.7% | Mar 2, 2020 | A SQL injection vulnerability in in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an u... |
| CVE-2019-19607 | CRITICAL | 9.8 | 1.7% | Mar 2, 2020 | A SQL injection vulnerability in the web conferencing component of Mitel MiCollab AWV before 8.1.2.2 could allow an unau... |
| CVE-2019-18903 | CRITICAL | 9.8 | 2.4% | Mar 2, 2020 | A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L... |
| CVE-2019-18902 | CRITICAL | 9.8 | 2.4% | Mar 2, 2020 | A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE L... |
| CVE-2019-14892 | CRITICAL | 9.8 | 5.4% | Mar 2, 2020 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymor... |
| CVE-2019-20489 | CRITICAL | 9.8 | 1.3% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. The web management interface (setup.cgi) has an authentic... |
| CVE-2019-20488 | CRITICAL | 9.8 | 2.1% | Mar 2, 2020 | An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (set... |
| CVE-2019-10804 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | serial-number through 1.3.0 allows execution of arbritary commands. The "cmdPrefix" argument in serialNumber function is... |
| CVE-2019-10803 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | push-dir through 0.4.1 allows execution of arbritary commands. Arguments provided as part of the variable "opt.branch" i... |
| CVE-2019-10802 | CRITICAL | 9.8 | 2.4% | Feb 28, 2020 | giting version prior to 0.0.8 allows execution of arbritary commands. The first argument "repo" of function "pull()" is ... |
| CVE-2019-10801 | CRITICAL | 9.8 | 2.8% | Feb 28, 2020 | enpeem through 2.2.0 allows execution of arbitrary commands. The "options.dir" argument is provided to the "exec" functi... |
| CVE-2019-15609 | CRITICAL | 9.8 | 3.9% | Feb 28, 2020 | The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. |
| CVE-2019-17275 | CRITICAL | 9.8 | 2.7% | Feb 26, 2020 | OnCommand Cloud Manager versions prior to 3.8.0 are susceptible to arbitrary code execution by remote attackers. |
| CVE-2019-19994 | CRITICAL | 9.8 | 4.8% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. A... |
| CVE-2019-5138 | CRITICAL | 9.9 | 5.4% | Feb 25, 2020 | An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A... |
| CVE-2019-12511 | CRITICAL | 9.8 | 2.3% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R9000 prior to 1.0.4.26, an attacker may execute arbitrary system commands as root by sending a... |
| CVE-2019-12510 | CRITICAL | 9.1 | 0.7% | Feb 24, 2020 | In NETGEAR Nighthawk X10-R900 prior to 1.0.4.26, an attacker may bypass all authentication checks on the device's "NETGE... |
| CVE-2019-10796 | CRITICAL | 9.8 | 2.7% | Feb 24, 2020 | rpi through 0.0.3 allows execution of arbritary commands. The variable pinNumbver in function GPIO within src/lib/gpio.j... |
| CVE-2019-20481 | CRITICAL | 9.8 | 0.6% | Feb 24, 2020 | In MIELE XGW 3000 ZigBee Gateway before 2.4.0, the Password Change Function does not require knowledge of the old passwo... |
| CVE-2019-18183 | CRITICAL | 9.8 | 3.7% | Feb 24, 2020 | pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. Thi... |
| CVE-2019-18182 | CRITICAL | 9.8 | 3.7% | Feb 24, 2020 | pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. Th... |
| CVE-2019-4640 | CRITICAL | 9.8 | 0.5% | Feb 19, 2020 | IBM Security Secret Server 10.7 processes patches, image backups and other updates without sufficiently verifying the or... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now