2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20478 | CRITICAL | 9.8 | 6.6% | Feb 19, 2020 | In ruamel.yaml through 0.16.7, the load method allows remote code execution if the application calls this method with an... |
| CVE-2019-20477 | CRITICAL | 9.8 | 5.0% | Feb 19, 2020 | PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserializa... |
| CVE-2019-10791 | CRITICAL | 9.8 | 2.0% | Feb 18, 2020 | promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and opti... |
| CVE-2019-5613 | CRITICAL | 9.8 | 0.6% | Feb 18, 2020 | In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an ... |
| CVE-2019-4392 | CRITICAL | 9.8 | 1.4% | Feb 14, 2020 | HCL AppScan Standard Edition 9.0.3.13 and earlier uses hard-coded credentials which can be exploited by attackers to get... |
| CVE-2019-20046 | CRITICAL | 9.8 | 2.2% | Feb 14, 2020 | The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and pri... |
| CVE-2019-14514 | CRITICAL | 9.8 | 7.0% | Feb 11, 2020 | An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu ... |
| CVE-2019-17137 | CRITICAL | 9.4 | 2.7% | Feb 10, 2020 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR AC120... |
| CVE-2019-20451 | CRITICAL | 9.8 | 7.5% | Feb 10, 2020 | The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by upload... |
| CVE-2019-20062 | CRITICAL | 9.8 | 1.6% | Feb 10, 2020 | MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash n... |
| CVE-2019-15606 | CRITICAL | 9.8 | 20.0% | Feb 7, 2020 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on he... |
| CVE-2019-15605 | CRITICAL | 9.8 | 57.1% | Feb 7, 2020 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |
| CVE-2019-17268 | CRITICAL | 9.8 | 2.4% | Feb 7, 2020 | The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserte... |
| CVE-2019-14063 | CRITICAL | 9.1 | 0.9% | Feb 7, 2020 | Out of bound access due to Invalid inputs to dapm mux settings which results into kernel failure in Snapdragon Auto, Sna... |
| CVE-2019-14057 | CRITICAL | 9.1 | 0.9% | Feb 7, 2020 | Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snap... |
| CVE-2019-10590 | CRITICAL | 9.8 | 0.9% | Feb 7, 2020 | Out of bound access while parsing dts atom, which is non-standard as it does not have valid number of tracks in Snapdrag... |
| CVE-2019-10789 | CRITICAL | 9.8 | 4.9% | Feb 6, 2020 | All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be control... |
| CVE-2019-20447 | CRITICAL | 9.8 | 2.0% | Feb 5, 2020 | Jobberbase 2.0 has SQL injection via the PATH_INFO to the jobs-in endpoint. |
| CVE-2019-10788 | CRITICAL | 9.8 | 2.4% | Feb 4, 2020 | im-metadata through 3.0.1 allows remote attackers to execute arbitrary commands via the "exec" argument. It is possible ... |
| CVE-2019-10787 | CRITICAL | 9.8 | 3.8% | Feb 4, 2020 | im-resize through 2.3.2 allows remote attackers to execute arbitrary commands via the "exec" argument. The cmd argument ... |
| CVE-2019-10786 | CRITICAL | 9.8 | 2.1% | Feb 4, 2020 | network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument. |
| CVE-2019-10784 | CRITICAL | 9.6 | 3.6% | Feb 4, 2020 | phppgadmin through 7.12.1 allows sensitive actions to be performed without validating that the request originated from t... |
| CVE-2019-4675 | CRITICAL | 9.8 | 1.3% | Feb 4, 2020 | IBM Security Identity Manager 7.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it u... |
| CVE-2019-10783 | CRITICAL | 9.8 | 2.6% | Jan 29, 2020 | All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the p... |
| CVE-2019-20445 | CRITICAL | 9.1 | 13.5% | Jan 29, 2020 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Lengt... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now