2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20074 | HIGH | 8.8 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via ... |
| CVE-2019-20073 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration). |
| CVE-2019-20072 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). |
| CVE-2019-20071 | MEDIUM | 6.5 | 0.7% | Dec 30, 2019 | On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. |
| CVE-2019-20070 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking... |
| CVE-2019-20063 | HIGH | 8.8 | 1.7% | Dec 29, 2019 | hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. |
| CVE-2019-20058 | MEDIUM | 6.1 | 0.7% | Dec 29, 2019 | Bolt 3.7.0, if Symfony Web Profiler is used, allows XSS because unsanitized search?search= input is shown on the _profil... |
| CVE-2019-20057 | LOW | 3.7 | 0.4% | Dec 29, 2019 | com.proxyman.NSProxy.HelperTool in Privileged Helper Tool in Proxyman for macOS 1.11.0 and earlier allows an attacker to... |
| CVE-2019-20056 | MEDIUM | 6.5 | 0.9% | Dec 29, 2019 | stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__s... |
| CVE-2019-20055 | MEDIUM | 6.5 | 0.9% | Dec 29, 2019 | LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets. |
| CVE-2019-20054 | MEDIUM | 5.5 | 0.5% | Dec 28, 2019 | In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, r... |
| CVE-2019-20053 | MEDIUM | 5.5 | 1.2% | Dec 27, 2019 | An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted M... |
| CVE-2019-20052 | MEDIUM | 6.5 | 1.1% | Dec 27, 2019 | A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0... |
| CVE-2019-20051 | MEDIUM | 5.5 | 0.9% | Dec 27, 2019 | A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability cause... |
| CVE-2019-20049 | CRITICAL | 9.8 | 12.8% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a director... |
| CVE-2019-20048 | HIGH | 7.2 | 5.8% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 8770 devices before 4.1.2. An authenticated remote attacker, with el... |
| CVE-2019-20047 | HIGH | 7.5 | 2.7% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server... |
| CVE-2019-16896 | HIGH | 7.8 | 0.4% | Dec 27, 2019 | In K7 Ultimate Security 16.0.0117, the module K7BKCExt.dll (aka the backup module) improperly validates the administrati... |
| CVE-2019-19781 | CRITICAL | 9.8 | 100.0% | Dec 27, 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th... |
| CVE-2019-20043 | MEDIUM | 4.3 | 2.5% | Dec 27, 2019 | In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users w... |
| CVE-2019-20042 | MEDIUM | 6.1 | 2.8% | Dec 27, 2019 | In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular... |
| CVE-2019-20041 | CRITICAL | 9.8 | 4.7% | Dec 27, 2019 | wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing... |
| CVE-2019-20024 | MEDIUM | 6.5 | 1.0% | Dec 27, 2019 | A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4. |
| CVE-2019-20023 | MEDIUM | 6.5 | 1.0% | Dec 27, 2019 | A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4. |
| CVE-2019-20022 | MEDIUM | 6.5 | 0.9% | Dec 27, 2019 | An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now