2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16674 | CRITICAL | 9.8 | 1.9% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-16673 | MEDIUM | 6.5 | 1.1% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-16672 | CRITICAL | 9.8 | 1.3% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-16671 | MEDIUM | 6.5 | 1.9% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-16670 | CRITICAL | 9.8 | 2.0% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-12734 | HIGH | 8.8 | 2.1% | Dec 6, 2019 | SiteVision 4 has Incorrect Access Control. |
| CVE-2019-12733 | HIGH | 8.8 | 6.0% | Dec 6, 2019 | SiteVision 4 allows Remote Code Execution. |
| CVE-2019-5544 | CRITICAL | 9.8 | 96.8% | Dec 6, 2019 | OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of... |
| CVE-2019-19627 | MEDIUM | 5.3 | 2.1% | Dec 6, 2019 | SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_... |
| CVE-2019-19625 | MEDIUM | 5.3 | 1.5% | Dec 6, 2019 | SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the under... |
| CVE-2019-19620 | LOW | 3.3 | 0.4% | Dec 6, 2019 | In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by rem... |
| CVE-2019-19552 | MEDIUM | 4.8 | 0.6% | Dec 6, 2019 | In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator ... |
| CVE-2019-19551 | MEDIUM | 4.8 | 0.6% | Dec 6, 2019 | In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator ... |
| CVE-2019-19334 | CRITICAL | 9.8 | 3.9% | Dec 6, 2019 | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi... |
| CVE-2019-19333 | CRITICAL | 9.8 | 3.6% | Dec 6, 2019 | In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG fi... |
| CVE-2019-11554 | MEDIUM | 5.9 | 0.5% | Dec 6, 2019 | The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM ... |
| CVE-2019-19624 | MEDIUM | 6.5 | 1.7% | Dec 6, 2019 | An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be grea... |
| CVE-2019-19619 | MEDIUM | 6.1 | 1.2% | Dec 6, 2019 | domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed b... |
| CVE-2019-19617 | CRITICAL | 9.8 | 2.6% | Dec 6, 2019 | phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/classes/Display/GitRevision.php an... |
| CVE-2019-19616 | MEDIUM | 4.3 | 0.7% | Dec 6, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for M... |
| CVE-2019-19609 | HIGH | 7.2 | 54.1% | Dec 5, 2019 | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c... |
| CVE-2019-16770 | HIGH | 7.5 | 1.9% | Dec 5, 2019 | In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reac... |
| CVE-2019-16768 | MEDIUM | 4.3 | 0.7% | Dec 5, 2019 | In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Sy... |
| CVE-2019-16769 | MEDIUM | 5.4 | 1.0% | Dec 5, 2019 | The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not prope... |
| CVE-2019-5098 | HIGH | 8.6 | 2.0% | Dec 5, 2019 | An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A speciall... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now