2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-6279ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnera...
CVE-2019-6275Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attac...
CVE-2019-6274Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote atta...
CVE-2019-6273download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
CVE-2019-6272Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker...
CVE-2019-5885Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable val...
CVE-2019-5729Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-...
CVE-2019-5723An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Passwords are stored using reversible encryption rather t...
CVE-2019-5722An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handl...
CVE-2019-5417A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary file...
CVE-2019-5416A path traversal vulnerability in localhost-now npm package version 1.0.2 allows the attackers to read content of arbitr...
CVE-2019-5414If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands du...
CVE-2019-5413An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
CVE-2019-0191Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in ...
CVE-2019-9835The receiver (aka bridge) component of Fujitsu Wireless Keyboard Set LX901 GK900 devices allows Keystroke Injection. Thi...
CVE-2019-9834The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor...
CVE-2019-9833The Screen Stream application through 3.0.15 for Android allows remote attackers to cause a denial of service via many s...
CVE-2019-9832The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m...
CVE-2019-9831The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via...
CVE-2019-9829Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art ...
CVE-2019-9825FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Inde...
CVE-2019-0206Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2019-0129Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially en...
CVE-2019-0122Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may all...
CVE-2019-0121Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potenti...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now