2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19746 | MEDIUM | 5.5 | 1.2% | Dec 12, 2019 | make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer o... |
| CVE-2019-19740 | CRITICAL | 9.8 | 5.8% | Dec 12, 2019 | Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. |
| CVE-2019-19726 | HIGH | 7.8 | 3.5% | Dec 12, 2019 | OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be... |
| CVE-2019-7004 | MEDIUM | 5.4 | 2.2% | Dec 12, 2019 | A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthoriz... |
| CVE-2019-5154 | HIGH | 8.8 | 2.6% | Dec 12, 2019 | An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A s... |
| CVE-2019-5093 | CRITICAL | 9.8 | 2.5% | Dec 12, 2019 | An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so ... |
| CVE-2019-5092 | HIGH | 8.8 | 2.5% | Dec 12, 2019 | An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image form... |
| CVE-2019-5091 | HIGH | 7.5 | 1.9% | Dec 12, 2019 | An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so... |
| CVE-2019-5090 | HIGH | 7.5 | 2.3% | Dec 12, 2019 | An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltd... |
| CVE-2019-5085 | CRITICAL | 9.8 | 3.4% | Dec 12, 2019 | An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, v... |
| CVE-2019-10695 | MEDIUM | 6.5 | 0.9% | Dec 12, 2019 | When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s us... |
| CVE-2019-10694 | CRITICAL | 9.8 | 1.1% | Dec 12, 2019 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the ins... |
| CVE-2019-3989 | CRITICAL | 9.8 | 3.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3988 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3987 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3986 | HIGH | 8.8 | 1.2% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3985 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3983 | MEDIUM | 6.8 | 1.0% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the de... |
| CVE-2019-18245 | HIGH | 7.8 | 0.4% | Dec 11, 2019 | Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th... |
| CVE-2019-18232 | HIGH | 7.8 | 0.4% | Dec 11, 2019 | SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulne... |
| CVE-2019-17087 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be e... |
| CVE-2019-0405 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con... |
| CVE-2019-0404 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading... |
| CVE-2019-0403 | CRITICAL | 9.8 | 2.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed whe... |
| CVE-2019-0402 | MEDIUM | 4.4 | 0.4% | Dec 11, 2019 | SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive informati... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now