2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16733 | CRITICAL | 9.8 | 3.6% | Dec 13, 2019 | processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attacke... |
| CVE-2019-16732 | HIGH | 8.1 | 0.9% | Dec 13, 2019 | Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run a... |
| CVE-2019-16731 | HIGH | 7.5 | 1.1% | Dec 13, 2019 | The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate... |
| CVE-2019-16730 | CRITICAL | 9.8 | 3.7% | Dec 13, 2019 | processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attack... |
| CVE-2019-19793 | HIGH | 8.8 | 1.0% | Dec 13, 2019 | In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain c... |
| CVE-2019-19790 | CRITICAL | 9.8 | 3.0% | Dec 13, 2019 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with exte... |
| CVE-2019-19774 | HIGH | 8.8 | 12.5% | Dec 13, 2019 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai... |
| CVE-2019-17123 | HIGH | 7.5 | 1.0% | Dec 13, 2019 | The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email)... |
| CVE-2019-19722 | MEDIUM | 5.3 | 2.5% | Dec 13, 2019 | In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications... |
| CVE-2019-4426 | MEDIUM | 5.4 | 0.7% | Dec 13, 2019 | The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable t... |
| CVE-2019-19787 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 fi... |
| CVE-2019-19786 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file. |
| CVE-2019-19785 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file. |
| CVE-2019-14344 | MEDIUM | 6.1 | 0.7% | Dec 13, 2019 | TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkRepl... |
| CVE-2019-5291 | MEDIUM | 5.9 | 0.4% | Dec 13, 2019 | Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated att... |
| CVE-2019-5290 | MEDIUM | 6.5 | 0.6% | Dec 13, 2019 | Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations... |
| CVE-2019-5251 | MEDIUM | 5.5 | 0.8% | Dec 13, 2019 | There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain... |
| CVE-2019-5250 | HIGH | 7.8 | 0.6% | Dec 13, 2019 | Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. ... |
| CVE-2019-5248 | HIGH | 7.4 | 0.3% | Dec 13, 2019 | CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets.... |
| CVE-2019-19397 | HIGH | 7.5 | 0.8% | Dec 13, 2019 | There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. A... |
| CVE-2019-17599 | MEDIUM | 6.1 | 1.7% | Dec 13, 2019 | The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting... |
| CVE-2019-19501 | HIGH | 7.8 | 0.5% | Dec 13, 2019 | VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe. |
| CVE-2019-18838 | HIGH | 7.5 | 2.1% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an int... |
| CVE-2019-18802 | CRITICAL | 9.8 | 2.5% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespa... |
| CVE-2019-18801 | CRITICAL | 9.8 | 2.5% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outs... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now