2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19372 | HIGH | 7.5 | 1.5% | Nov 28, 2019 | A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in... |
| CVE-2019-18276 | HIGH | 7.8 | 2.6% | Nov 28, 2019 | An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run wit... |
| CVE-2019-19318 | MEDIUM | 4.4 | 0.6% | Nov 28, 2019 | In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free b... |
| CVE-2019-19319 | MEDIUM | 6.5 | 0.7% | Nov 27, 2019 | In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bou... |
| CVE-2019-18660 | MEDIUM | 4.7 | 0.7% | Nov 27, 2019 | The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place ... |
| CVE-2019-18253 | CRITICAL | 10 | 2.0% | Nov 27, 2019 | An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (vers... |
| CVE-2019-18247 | HIGH | 7.5 | 1.6% | Nov 27, 2019 | An attacker may use a specially crafted message to force Relion 650 series (versions 1.3.0.5 and prior) or Relion 670 se... |
| CVE-2019-6673 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On versions 15.0.0-15.0.1 and 14.0.0-14.1.2, when the BIG-IP is configured in HTTP/2 Full Proxy mode, specifically craft... |
| CVE-2019-6672 | HIGH | 7.5 | 1.2% | Nov 27, 2019 | On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, and 13.1.0-13.1.3.1, when bad-actor detection is configured on a wildcard vi... |
| CVE-2019-6671 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, under certain conditions tmm may leak memory... |
| CVE-2019-6670 | MEDIUM | 4.4 | 0.2% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hyperviso... |
| CVE-2019-6669 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, undisclosed ... |
| CVE-2019-6668 | MEDIUM | 5.5 | 0.3% | Nov 27, 2019 | The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.... |
| CVE-2019-6667 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.5.1-11.6.5, under ce... |
| CVE-2019-6666 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, and 13.1.0-13.1.1.4, the TMM process may produce a core file ... |
| CVE-2019-6665 | CRITICAL | 9.4 | 1.1% | Nov 27, 2019 | On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow ... |
| CVE-2019-6674 | HIGH | 7.5 | 1.0% | Nov 27, 2019 | On F5 SSL Orchestrator 15.0.0-15.0.1 and 14.0.0-14.1.2, TMM may crash when processing SSLO data in a service-chaining co... |
| CVE-2019-15705 | HIGH | 7.5 | 1.3% | Nov 27, 2019 | An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and belo... |
| CVE-2019-19367 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject... |
| CVE-2019-19366 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers ... |
| CVE-2019-19242 | MEDIUM | 5.9 | 2.5% | Nov 27, 2019 | SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. |
| CVE-2019-19330 | CRITICAL | 9.8 | 3.9% | Nov 27, 2019 | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd... |
| CVE-2019-19329 | MEDIUM | 6.1 | 1.4% | Nov 27, 2019 | In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are di... |
| CVE-2019-19328 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection i... |
| CVE-2019-19327 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when repo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now