2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5225 | HIGH | 7.8 | 0.8% | Nov 29, 2019 | P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions ea... |
| CVE-2019-5224 | MEDIUM | 5.5 | 0.6% | Nov 29, 2019 | P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. ... |
| CVE-2019-5218 | HIGH | 8.8 | 0.4% | Nov 29, 2019 | There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently ... |
| CVE-2019-5212 | MEDIUM | 5.5 | 0.5% | Nov 29, 2019 | There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to cer... |
| CVE-2019-5211 | MEDIUM | 5.7 | 0.3% | Nov 29, 2019 | The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management ... |
| CVE-2019-5210 | HIGH | 7.8 | 0.3% | Nov 29, 2019 | Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(... |
| CVE-2019-5226 | MEDIUM | 5.5 | 0.2% | Nov 29, 2019 | P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear... |
| CVE-2019-18922 | HIGH | 7.5 | 24.7% | Nov 29, 2019 | A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] al... |
| CVE-2019-16767 | HIGH | 7.2 | 0.8% | Nov 29, 2019 | The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance ... |
| CVE-2019-19378 | HIGH | 7.8 | 2.3% | Nov 29, 2019 | In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in ind... |
| CVE-2019-16766 | HIGH | 8.8 | 1.2% | Nov 29, 2019 | When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into t... |
| CVE-2019-19391 | CRITICAL | 9.1 | 1.3% | Nov 29, 2019 | In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue th... |
| CVE-2019-19377 | HIGH | 7.8 | 3.4% | Nov 29, 2019 | In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can le... |
| CVE-2019-14901 | CRITICAL | 9.8 | 16.9% | Nov 29, 2019 | A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri... |
| CVE-2019-14897 | CRITICAL | 9.8 | 2.9% | Nov 29, 2019 | A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An atta... |
| CVE-2019-14895 | CRITICAL | 9.8 | 7.8% | Nov 29, 2019 | A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell ... |
| CVE-2019-14865 | MEDIUM | 5.9 | 0.3% | Nov 29, 2019 | A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pres... |
| CVE-2019-19388 | MEDIUM | 6.1 | 0.9% | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote at... |
| CVE-2019-19387 | MEDIUM | 6.1 | 0.9% | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attack... |
| CVE-2019-19386 | MEDIUM | 6.1 | 0.9% | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 all... |
| CVE-2019-19385 | MEDIUM | 6.1 | 0.9% | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to ... |
| CVE-2019-19384 | MEDIUM | 6.1 | 0.9% | Nov 29, 2019 | A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inj... |
| CVE-2019-19379 | MEDIUM | 5.3 | 1.1% | Nov 28, 2019 | In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data. |
| CVE-2019-19376 | MEDIUM | 6.5 | 1.0% | Nov 28, 2019 | In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API reque... |
| CVE-2019-19375 | MEDIUM | 5.3 | 0.4% | Nov 28, 2019 | In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes se... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now