2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4651 | CRITICAL | 9.8 | 1.4% | Jan 9, 2020 | IBM Jazz Reporting Service (JRS) 6.0.6.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted ... |
| CVE-2019-9812 | CRITICAL | 9.3 | 1.3% | Jan 8, 2020 | Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by ... |
| CVE-2019-19495 | CRITICAL | 9.8 | 4.3% | Jan 8, 2020 | The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to... |
| CVE-2019-5082 | CRITICAL | 9.8 | 3.3% | Jan 8, 2020 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 ... |
| CVE-2019-20367 | CRITICAL | 9.1 | 2.8% | Jan 8, 2020 | nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (s... |
| CVE-2019-10777 | CRITICAL | 9.8 | 1.6% | Jan 8, 2020 | In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within th... |
| CVE-2019-19518 | CRITICAL | 9.8 | 2.8% | Jan 8, 2020 | CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server ... |
| CVE-2019-17076 | CRITICAL | 9.8 | 2.5% | Jan 8, 2020 | An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in ... |
| CVE-2019-10778 | CRITICAL | 9.8 | 3.5% | Jan 8, 2020 | devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the ex... |
| CVE-2019-20361 | CRITICAL | 9.8 | 85.1% | Jan 8, 2020 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b... |
| CVE-2019-17146 | CRITICAL | 9.8 | 9.5% | Jan 7, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link DCS-960L v1.07.... |
| CVE-2019-14906 | CRITICAL | 9.8 | 1.8% | Jan 7, 2020 | A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue ... |
| CVE-2019-10776 | CRITICAL | 9.8 | 2.1% | Jan 7, 2020 | In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. ... |
| CVE-2019-14837 | CRITICAL | 9.1 | 1.7% | Jan 7, 2020 | A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this ... |
| CVE-2019-16273 | CRITICAL | 9.8 | 2.3% | Jan 6, 2020 | DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading ... |
| CVE-2019-16272 | CRITICAL | 9.8 | 1.2% | Jan 6, 2020 | On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enab... |
| CVE-2019-18792 | CRITICAL | 9.1 | 2.5% | Jan 6, 2020 | An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP s... |
| CVE-2019-20343 | CRITICAL | 9.8 | 2.4% | Jan 6, 2020 | The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration ... |
| CVE-2019-15976 | CRITICAL | 9.8 | 92.8% | Jan 6, 2020 | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an una... |
| CVE-2019-15975 | CRITICAL | 9.8 | 85.6% | Jan 6, 2020 | Multiple vulnerabilities in the authentication mechanisms of Cisco Data Center Network Manager (DCNM) could allow an una... |
| CVE-2019-19628 | CRITICAL | 9.8 | 3.6% | Jan 5, 2020 | In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry... |
| CVE-2019-11994 | CRITICAL | 9.8 | 7.2% | Jan 3, 2020 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 ... |
| CVE-2019-19088 | CRITICAL | 9.8 | 1.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. |
| CVE-2019-20330 | CRITICAL | 9.8 | 8.6% | Jan 3, 2020 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. |
| CVE-2019-14859 | CRITICAL | 9.1 | 1.6% | Jan 2, 2020 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used D... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now