2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9976 | — | — | 1.0% | Apr 11, 2019 | The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, w... |
| CVE-2019-9975 | — | — | 1.3% | Apr 11, 2019 | DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be... |
| CVE-2019-9974 | — | — | 2.9% | Apr 11, 2019 | diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote at... |
| CVE-2019-9733 | — | — | 53.9% | Apr 11, 2019 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password o... |
| CVE-2019-7219 | — | — | 5.2% | Apr 11, 2019 | Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a di... |
| CVE-2019-5715 | — | — | 1.6% | Apr 11, 2019 | All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4... |
| CVE-2019-6610 | — | — | 1.1% | Apr 11, 2019 | On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vu... |
| CVE-2019-5673 | — | — | 0.3% | Apr 11, 2019 | NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Me... |
| CVE-2019-5672 | — | — | 1.4% | Apr 11, 2019 | NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior t... |
| CVE-2019-6318 | — | — | 2.6% | Apr 11, 2019 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise ... |
| CVE-2019-3916 | — | — | 2.1% | Apr 11, 2019 | Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remo... |
| CVE-2019-3915 | — | — | 0.6% | Apr 11, 2019 | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.... |
| CVE-2019-3914 | — | — | 29.9% | Apr 11, 2019 | Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a rem... |
| CVE-2019-11078 | — | — | 0.6% | Apr 11, 2019 | MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. |
| CVE-2019-11072 | — | — | 73.8% | Apr 10, 2019 | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (a... |
| CVE-2019-11071 | — | — | 2.6% | Apr 10, 2019 | SPIP 3.1 before 3.1.10 and 3.2 before 3.2.4 allows authenticated visitors to execute arbitrary code on the host server b... |
| CVE-2019-11070 | — | — | 3.2% | Apr 10, 2019 | WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloadin... |
| CVE-2019-11069 | — | — | 1.8% | Apr 10, 2019 | Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used. |
| CVE-2019-0285 | — | — | 6.6% | Apr 10, 2019 | The .NET SDK WebForm Viewer in SAP Crystal Reports for Visual Studio (fixed in version 2010) discloses sensitive databas... |
| CVE-2019-0284 | — | — | 0.4% | Apr 10, 2019 | SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from a... |
| CVE-2019-0283 | — | — | 0.6% | Apr 10, 2019 | SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; is vulnerabl... |
| CVE-2019-0282 | — | — | 1.2% | Apr 10, 2019 | Several web pages in SAP NetWeaver Process Integration (Runtime Workbench), fixed in versions 7.10 to 7.11, 7.30, 7.31, ... |
| CVE-2019-0279 | — | — | 1.1% | Apr 10, 2019 | ABAP BASIS function modules INST_CREATE_R3_RFC_DEST, INST_CREATE_TCPIP_RFCDEST, and INST_CREATE_TCPIP_RFC_DEST in SAP BA... |
| CVE-2019-0278 | — | — | 0.7% | Apr 10, 2019 | Under certain conditions the Monitoring Servlet of the SAP NetWeaver Process Integration (Messaging System), fixed in ve... |
| CVE-2019-9694 | — | — | 0.2% | Apr 10, 2019 | Symantec Endpoint Encryption prior to SEE 11.2.1 MP1 may be susceptible to a Privilege Escalation vulnerability, which i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now