2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20444 | CRITICAL | 9.1 | 8.7% | Jan 29, 2020 | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a ... |
| CVE-2019-20217 | CRITICAL | 9.8 | 3.6% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t... |
| CVE-2019-20216 | CRITICAL | 9.8 | 3.7% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t... |
| CVE-2019-20215 | CRITICAL | 9.8 | 75.1% | Jan 29, 2020 | D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the... |
| CVE-2019-5464 | CRITICAL | 9.8 | 2.8% | Jan 28, 2020 | A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which coul... |
| CVE-2019-15585 | CRITICAL | 9.8 | 1.6% | Jan 28, 2020 | Improper authentication exists in < 12.3.2, < 12.2.6, and < 12.1.12 for GitLab Community Edition (CE) and Enterprise Edi... |
| CVE-2019-8257 | CRITICAL | 9.8 | 4.1% | Jan 28, 2020 | Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20... |
| CVE-2019-7131 | CRITICAL | 9.8 | 4.3% | Jan 28, 2020 | Adobe Acrobat and Reader versions 2019.010.20064 and earlier, 2019.010.20064 and earlier, 2017.011.30110 and earlier ver... |
| CVE-2019-17095 | CRITICAL | 9.8 | 4.2% | Jan 27, 2020 | A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 an... |
| CVE-2019-19825 | CRITICAL | 9.8 | 29.6% | Jan 27, 2020 | On certain TOTOLINK Realtek SDK based routers, the CAPTCHA text can be retrieved via an {"topicurl":"setting/getSanvas"}... |
| CVE-2019-17096 | CRITICAL | 9.8 | 2.1% | Jan 27, 2020 | A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_ima... |
| CVE-2019-20433 | CRITICAL | 9.1 | 1.7% | Jan 27, 2020 | libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encod... |
| CVE-2019-20427 | CRITICAL | 9.8 | 4.9% | Jan 27, 2020 | In the Lustre file system before 2.12.3, the ptlrpc module has a buffer overflow and panic, and possibly remote code exe... |
| CVE-2019-16029 | CRITICAL | 9.1 | 1.1% | Jan 26, 2020 | A vulnerability in the application programming interface (API) of Cisco Smart Software Manager On-Prem could allow an un... |
| CVE-2019-5183 | CRITICAL | 9 | 1.8% | Jan 25, 2020 | An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.1... |
| CVE-2019-1353 | CRITICAL | 9.8 | 2.2% | Jan 24, 2020 | An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.... |
| CVE-2019-17570 | CRITICAL | 9.8 | 49.3% | Jan 23, 2020 | An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache X... |
| CVE-2019-19897 | CRITICAL | 9.8 | 5.6% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can comm... |
| CVE-2019-19896 | CRITICAL | 9.9 | 3.0% | Jan 23, 2020 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The defau... |
| CVE-2019-16517 | CRITICAL | 9.8 | 1.3% | Jan 23, 2020 | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS miscon... |
| CVE-2019-16153 | CRITICAL | 9.8 | 1.1% | Jan 23, 2020 | A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attac... |
| CVE-2019-19839 | CRITICAL | 9.8 | 3.3% | Jan 23, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19838 | CRITICAL | 9.8 | 24.4% | Jan 23, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19842 | CRITICAL | 9.8 | 5.0% | Jan 22, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
| CVE-2019-19841 | CRITICAL | 9.8 | 3.3% | Jan 22, 2020 | emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now