2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8525 | MEDIUM | 6.7 | 0.4% | Oct 27, 2020 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Sec... |
| CVE-2019-7291 | MEDIUM | 6.5 | 1.1% | Oct 27, 2020 | A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmw... |
| CVE-2019-14718 | MEDIUM | 6.7 | 1.2% | Oct 23, 2020 | Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol... |
| CVE-2019-14716 | MEDIUM | 6.6 | 0.3% | Oct 23, 2020 | Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out). |
| CVE-2019-14715 | MEDIUM | 6.8 | 0.3% | Oct 23, 2020 | Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write op... |
| CVE-2019-14713 | MEDIUM | 5.5 | 0.3% | Oct 23, 2020 | Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages. |
| CVE-2019-16128 | MEDIUM | 6.8 | 0.6% | Oct 22, 2020 | Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2). |
| CVE-2019-16129 | MEDIUM | 6.8 | 0.6% | Oct 22, 2020 | Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2). |
| CVE-2019-13633 | MEDIUM | 6.1 | 1.0% | Oct 19, 2020 | Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-... |
| CVE-2019-12305 | MEDIUM | 6.5 | 0.5% | Oct 16, 2020 | In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access... |
| CVE-2019-18796 | MEDIUM | 6.5 | 0.9% | Oct 16, 2020 | The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinit... |
| CVE-2019-18795 | MEDIUM | 6.5 | 1.3% | Oct 16, 2020 | The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a c... |
| CVE-2019-18794 | MEDIUM | 6.5 | 1.1% | Oct 16, 2020 | The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a craft... |
| CVE-2019-4552 | MEDIUM | 6.1 | 0.9% | Oct 15, 2020 | IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attack... |
| CVE-2019-4325 | MEDIUM | 5.3 | 0.5% | Oct 6, 2020 | "HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details." |
| CVE-2019-4725 | MEDIUM | 6.1 | 0.7% | Oct 6, 2020 | IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2019-14558 | MEDIUM | 5.7 | 0.7% | Oct 5, 2020 | Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(... |
| CVE-2019-14556 | MEDIUM | 4.4 | 0.3% | Oct 5, 2020 | Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor ... |
| CVE-2019-19393 | MEDIUM | 6.1 | 0.8% | Oct 1, 2020 | The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on... |
| CVE-2019-20903 | MEDIUM | 5.4 | 1.1% | Oct 1, 2020 | The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitra... |
| CVE-2019-20921 | MEDIUM | 6.1 | 1.7% | Sep 30, 2020 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. Th... |
| CVE-2019-18991 | MEDIUM | 5.4 | 0.5% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d... |
| CVE-2019-18990 | MEDIUM | 5.4 | 0.8% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RT... |
| CVE-2019-18989 | MEDIUM | 5.4 | 0.8% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending ... |
| CVE-2019-17098 | MEDIUM | 6.5 | 0.5% | Sep 30, 2020 | Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacke... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now