2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6279 | — | — | 7.5% | Mar 21, 2019 | ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera... |
| CVE-2019-6275 | — | — | 12.5% | Mar 21, 2019 | Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac... |
| CVE-2019-6274 | — | — | 11.4% | Mar 21, 2019 | Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote atta... |
| CVE-2019-6273 | — | — | 11.7% | Mar 21, 2019 | download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files. |
| CVE-2019-6272 | — | — | 12.5% | Mar 21, 2019 | Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker... |
| CVE-2019-5885 | — | — | 2.4% | Mar 21, 2019 | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable val... |
| CVE-2019-5729 | — | — | 0.5% | Mar 21, 2019 | Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-... |
| CVE-2019-5723 | — | — | 1.1% | Mar 21, 2019 | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather t... |
| CVE-2019-5722 | — | — | 3.9% | Mar 21, 2019 | An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handl... |
| CVE-2019-5417 | — | — | 2.2% | Mar 21, 2019 | A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary file... |
| CVE-2019-5416 | — | — | 2.2% | Mar 21, 2019 | A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitr... |
| CVE-2019-5414 | — | — | 1.9% | Mar 21, 2019 | If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands du... |
| CVE-2019-5413 | — | — | 3.4% | Mar 21, 2019 | An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1. |
| CVE-2019-0191 | — | — | 4.9% | Mar 21, 2019 | Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in ... |
| CVE-2019-9835 | — | — | 0.6% | Mar 15, 2019 | The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. Thi... |
| CVE-2019-9834 | — | — | 5.1% | Mar 15, 2019 | The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor... |
| CVE-2019-9833 | — | — | 8.8% | Mar 15, 2019 | The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many s... |
| CVE-2019-9832 | — | — | 8.3% | Mar 15, 2019 | The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m... |
| CVE-2019-9831 | — | — | 9.0% | Mar 15, 2019 | The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via... |
| CVE-2019-9829 | — | — | 2.0% | Mar 15, 2019 | Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art ... |
| CVE-2019-9825 | — | — | 2.2% | Mar 14, 2019 | FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Inde... |
| CVE-2019-0206 | — | — | — | Mar 14, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-0129 | — | — | 0.4% | Mar 14, 2019 | Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially en... |
| CVE-2019-0122 | — | — | 0.3% | Mar 14, 2019 | Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may all... |
| CVE-2019-0121 | — | — | 0.4% | Mar 14, 2019 | Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potenti... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now