2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19546 | MEDIUM | 6.5 | 0.9% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vul... |
| CVE-2019-19545 | MEDIUM | 6.3 | 0.3% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w... |
| CVE-2019-18381 | MEDIUM | 6.3 | 0.3% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w... |
| CVE-2019-17388 | HIGH | 7.8 | 0.6% | Dec 5, 2019 | Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allo... |
| CVE-2019-17387 | HIGH | 7.8 | 0.7% | Dec 5, 2019 | An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated... |
| CVE-2019-7195 | CRITICAL | 9.8 | 89.7% | Dec 5, 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi... |
| CVE-2019-7194 | CRITICAL | 9.8 | 83.0% | Dec 5, 2019 | This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi... |
| CVE-2019-7193 | CRITICAL | 9.8 | 14.4% | Dec 5, 2019 | This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the ... |
| CVE-2019-7192 | CRITICAL | 9.8 | 88.2% | Dec 5, 2019 | This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the... |
| CVE-2019-7185 | MEDIUM | 4.8 | 1.5% | Dec 5, 2019 | This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on ... |
| CVE-2019-7184 | MEDIUM | 4.8 | 1.5% | Dec 5, 2019 | This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on ... |
| CVE-2019-7183 | CRITICAL | 9.8 | 1.6% | Dec 5, 2019 | This improper link resolution vulnerability allows remote attackers to access system files. To fix this vulnerability, Q... |
| CVE-2019-19466 | MEDIUM | 6.1 | 0.7% | Dec 5, 2019 | SCEditor 2.1.3 allows XSS. |
| CVE-2019-3690 | HIGH | 7.8 | 0.4% | Dec 5, 2019 | The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (pl... |
| CVE-2019-19595 | CRITICAL | 9.8 | 4.0% | Dec 5, 2019 | reset/modules/advanced_form_maker_edit/multiupload/upload.php in the RESET.PRO Adobe Stock API integration 4.8 for Prest... |
| CVE-2019-19594 | CRITICAL | 9.8 | 4.0% | Dec 5, 2019 | reset/modules/fotoliaFoto/multi_upload.php in the RESET.PRO Adobe Stock API Integration for PrestaShop 1.6 and 1.7 allow... |
| CVE-2019-19008 | — | — | — | Dec 5, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-19363. Reason: This candidate is a reservation d... |
| CVE-2019-19007 | HIGH | 7.2 | 1.6% | Dec 5, 2019 | Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user i... |
| CVE-2019-15897 | CRITICAL | 9.6 | 3.0% | Dec 5, 2019 | beegfs-ctl in ThinkParQ BeeGFS through 7.1.3 allows Authentication Bypass via communication with a BeeGFS metadata serve... |
| CVE-2019-11255 | MEDIUM | 6.5 | 1.7% | Dec 5, 2019 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2... |
| CVE-2019-18180 | HIGH | 7.5 | 1.9% | Dec 5, 2019 | Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attac... |
| CVE-2019-17437 | HIGH | 7.8 | 0.3% | Dec 5, 2019 | An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser cu... |
| CVE-2019-14910 | CRITICAL | 9.8 | 1.1% | Dec 5, 2019 | A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used in... |
| CVE-2019-19602 | MEDIUM | 6.1 | 0.6% | Dec 5, 2019 | fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows c... |
| CVE-2019-19317 | CRITICAL | 9.8 | 4.3% | Dec 5, 2019 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which al... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now