2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16733CRITICAL9.8processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attacke...
CVE-2019-16732HIGH8.1Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run a...
CVE-2019-16731HIGH7.5The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate...
CVE-2019-16730CRITICAL9.8processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attack...
CVE-2019-19793HIGH8.8In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain c...
CVE-2019-19790CRITICAL9.8Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with exte...
CVE-2019-19774HIGH8.8An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai...
CVE-2019-17123HIGH7.5The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email)...
CVE-2019-19722MEDIUM5.3In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications...
CVE-2019-4426MEDIUM5.4The Case Builder component shipped with 18.0.0.1 through 19.0.0.2 and IBM Case Manager 5.1.1 through 5.3 is vulnerable t...
CVE-2019-19787HIGH7.8ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 fi...
CVE-2019-19786HIGH7.8ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
CVE-2019-19785HIGH7.8ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.
CVE-2019-14344MEDIUM6.1TemaTres 3.0 has reflected XSS via the replace_string or search_string parameter to the vocab/admin.php?doAdmin=bulkRepl...
CVE-2019-5291MEDIUM5.9Some Huawei products have an insufficient verification of data authenticity vulnerability. A remote, unauthenticated att...
CVE-2019-5290MEDIUM6.5Huawei S5700 and S6700 have a DoS security vulnerability. Attackers with certain permissions perform specific operations...
CVE-2019-5251MEDIUM5.5There is a path traversal vulnerability in several Huawei smartphones. The system does not sufficiently validate certain...
CVE-2019-5250HIGH7.8Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. ...
CVE-2019-5248HIGH7.4CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets....
CVE-2019-19397HIGH7.5There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. A...
CVE-2019-17599MEDIUM6.1The quiz-master-next (aka Quiz And Survey Master) plugin before 6.3.5 for WordPress is affected by: Cross Site Scripting...
CVE-2019-19501HIGH7.8VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe.
CVE-2019-18838HIGH7.5An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an int...
CVE-2019-18802CRITICAL9.8An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespa...
CVE-2019-18801CRITICAL9.8An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outs...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now