2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10158 | CRITICAL | 9.8 | 2.0% | Jan 2, 2020 | A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protecti... |
| CVE-2019-3984 | CRITICAL | 9.8 | 3.8% | Dec 31, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-7162 | CRITICAL | 9.1 | 4.0% | Dec 31, 2019 | An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthentic... |
| CVE-2019-7478 | CRITICAL | 9.8 | 1.1% | Dec 31, 2019 | A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS... |
| CVE-2019-13445 | CRITICAL | 9.8 | 2.2% | Dec 30, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3... |
| CVE-2019-19735 | CRITICAL | 9.1 | 0.8% | Dec 30, 2019 | class.userpeer.php in MFScripts YetiShare 3.5.2 through 4.5.3 uses an insecure method of creating password reset hashes ... |
| CVE-2019-17621 | CRITICAL | 9.8 | 89.6% | Dec 30, 2019 | The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem... |
| CVE-2019-10774 | CRITICAL | 9.8 | 4.6% | Dec 30, 2019 | php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arb... |
| CVE-2019-16535 | CRITICAL | 9.8 | 1.7% | Dec 30, 2019 | In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can... |
| CVE-2019-20049 | CRITICAL | 9.8 | 12.8% | Dec 27, 2019 | An issue was discovered on Alcatel-Lucent OmniVista 4760 devices. A remote unauthenticated attacker can chain a director... |
| CVE-2019-19781 | CRITICAL | 9.8 | 100.0% | Dec 27, 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th... |
| CVE-2019-20041 | CRITICAL | 9.8 | 4.7% | Dec 27, 2019 | wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing... |
| CVE-2019-19398 | CRITICAL | 9.8 | 1.4% | Dec 26, 2019 | M5 lite 10 with versions of 8.0.0.182(C00) have an insufficient input validation vulnerability. Due to the input validat... |
| CVE-2019-16327 | CRITICAL | 9.8 | 1.8% | Dec 26, 2019 | D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the se... |
| CVE-2019-19977 | CRITICAL | 9.8 | 3.1% | Dec 26, 2019 | libESMTP through 1.0.6 mishandles domain copying into a fixed-size buffer in ntlm_build_type_2 in ntlm/ntlmstruct.c, as ... |
| CVE-2019-10758 | CRITICAL | 9.9 | 84.8% | Dec 24, 2019 | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse... |
| CVE-2019-19953 | CRITICAL | 9.1 | 2.8% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders... |
| CVE-2019-19952 | CRITICAL | 9.8 | 2.2% | Dec 24, 2019 | In ImageMagick 7.0.9-7 Q16, there is a use-after-free in the function MngInfoDiscardObject of coders/png.c, related to R... |
| CVE-2019-19951 | CRITICAL | 9.8 | 2.5% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of cod... |
| CVE-2019-19950 | CRITICAL | 9.8 | 2.7% | Dec 24, 2019 | In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magi... |
| CVE-2019-19949 | CRITICAL | 9.1 | 2.9% | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, relat... |
| CVE-2019-19948 | CRITICAL | 9.8 | 3.7% | Dec 24, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c. |
| CVE-2019-12568 | CRITICAL | 9.8 | 2.3% | Dec 23, 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server SP 1.66 and earlier allows remote attacke... |
| CVE-2019-12567 | CRITICAL | 9.8 | 2.3% | Dec 23, 2019 | Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attacke... |
| CVE-2019-8293 | CRITICAL | 9.8 | 2.6% | Dec 23, 2019 | Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now