2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15598 | CRITICAL | 9.8 | 2.7% | Dec 18, 2019 | A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control ... |
| CVE-2019-15597 | CRITICAL | 9.8 | 2.7% | Dec 18, 2019 | A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. |
| CVE-2019-15596 | HIGH | 7.5 | 1.5% | Dec 18, 2019 | A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a syml... |
| CVE-2019-15591 | MEDIUM | 6.5 | 1.1% | Dec 18, 2019 | An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and depend... |
| CVE-2019-15589 | HIGH | 8.8 | 1.1% | Dec 18, 2019 | An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user... |
| CVE-2019-15580 | MEDIUM | 6.5 | 1.1% | Dec 18, 2019 | An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking mer... |
| CVE-2019-15577 | MEDIUM | 4.3 | 0.7% | Dec 18, 2019 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project mi... |
| CVE-2019-15576 | HIGH | 7.5 | 1.9% | Dec 18, 2019 | An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacke... |
| CVE-2019-15575 | HIGH | 7.5 | 2.4% | Dec 18, 2019 | A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands... |
| CVE-2019-7621 | MEDIUM | 5.4 | 0.7% | Dec 18, 2019 | Kibana versions before 6.8.6 and 7.5.1 contain a cross site scripting (XSS) flaw in the coordinate and region map visual... |
| CVE-2019-5081 | CRITICAL | 9.8 | 4.5% | Dec 18, 2019 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service ''I/O-Chec'' functionality of WAGO PFC ... |
| CVE-2019-5077 | CRITICAL | 9.1 | 1.6% | Dec 18, 2019 | An exploitable denial-of-service vulnerability exists in the iocheckd service ‘’I/O-Chec’’ functionality of WAGO PFC 200... |
| CVE-2019-5074 | CRITICAL | 9.8 | 3.3% | Dec 18, 2019 | An exploitable stack buffer overflow vulnerability exists in the iocheckd service ''I/O-Check'' functionality of WAGO PF... |
| CVE-2019-19690 | CRITICAL | 9.8 | 1.5% | Dec 18, 2019 | Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an at... |
| CVE-2019-19689 | HIGH | 7.8 | 0.6% | Dec 18, 2019 | Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vul... |
| CVE-2019-19688 | HIGH | 7.8 | 0.6% | Dec 18, 2019 | A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exp... |
| CVE-2019-18267 | MEDIUM | 5.4 | 1.6% | Dec 18, 2019 | An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An att... |
| CVE-2019-16782 | MEDIUM | 5.9 | 3.7% | Dec 18, 2019 | There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched... |
| CVE-2019-11995 | HIGH | 7.5 | 2.1% | Dec 18, 2019 | Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data... |
| CVE-2019-19890 | HIGH | 7.5 | 1.0% | Dec 18, 2019 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over ... |
| CVE-2019-19889 | HIGH | 7.5 | 1.1% | Dec 18, 2019 | An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. The attacker can discover admin ... |
| CVE-2019-19888 | MEDIUM | 6.5 | 1.1% | Dec 18, 2019 | jfif_decode in jfif.c in ffjpeg through 2019-08-21 has a divide-by-zero error. |
| CVE-2019-19887 | MEDIUM | 6.5 | 1.1% | Dec 18, 2019 | bitstr_tell at bitstr.c in ffjpeg through 2019-08-21 has a NULL pointer dereference related to jfif_encode. |
| CVE-2019-19844 | CRITICAL | 9.8 | 34.8% | Dec 18, 2019 | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address ... |
| CVE-2019-8849 | CRITICAL | 9.8 | 2.2% | Dec 18, 2019 | The issue was addressed by signaling that an executable stack is not required. This issue is fixed in SwiftNIO SSL 2.4.1... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now