2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19160 | HIGH | 8.8 | 0.6% | Jun 29, 2020 | Reportexpress ProPlus contains a vulnerability that could allow an arbitrary code execution by inserted VBscript into th... |
| CVE-2019-20413 | HIGH | 7.5 | 2.1% | Jun 29, 2020 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to impact the application's availabili... |
| CVE-2019-19506 | HIGH | 7.5 | 1.1% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a denial of service, caused by an error in the "homeplugd" ... |
| CVE-2019-19505 | HIGH | 8.8 | 3.5% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 is vulnerable to a stack-based buffer overflow, caused by improper bounds ch... |
| CVE-2019-16213 | HIGH | 8.8 | 2.9% | Jun 25, 2020 | Tenda PA6 Wi-Fi Powerline extender 1.0.1.21 could allow a remote authenticated attacker to execute arbitrary commands on... |
| CVE-2019-14894 | HIGH | 7.2 | 4.1% | Jun 22, 2020 | A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere... |
| CVE-2019-14094 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Integer overflow in diag command handler when user inputs a large value for number of tasks field in the request packet ... |
| CVE-2019-14091 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Double free issue in NPU due to lack of resource locking mechanism to avoid race condition in Snapdragon Auto, Snapdrago... |
| CVE-2019-14076 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | Buffer overflow occurs while processing an subsample data length out of range due to lack of user input validation in Sn... |
| CVE-2019-14047 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | While IPA driver processes route add rule IOCTL, there is no input validation of the rule ID prior to adding the rule to... |
| CVE-2019-10597 | HIGH | 7.8 | 0.2% | Jun 22, 2020 | kernel writes to user passed address without any checks can lead to arbitrary memory write in Snapdragon Auto, Snapdrago... |
| CVE-2019-20891 | HIGH | 8.8 | 0.5% | Jun 19, 2020 | WooCommerce before 3.6.5, when it handles CSV imports of products, has a cross-site request forgery (CSRF) issue with re... |
| CVE-2019-20888 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It allows attackers to cause a denial... |
| CVE-2019-20886 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. The first user is sometimes inadvertently a system admin. |
| CVE-2019-20885 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It does not always generate a robots.txt file. |
| CVE-2019-20881 | HIGH | 7.3 | 0.8% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0. It mishandles brute-force attacks against MFA. |
| CVE-2019-20880 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.8.0, 5.7.2, 5.6.5, and 4.10.7. It allows attackers to cause a deni... |
| CVE-2019-20874 | HIGH | 7.5 | 1.2% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. It allows attackers to obtain sensi... |
| CVE-2019-20871 | HIGH | 7.5 | 1.1% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.9.0, 5.8.1, 5.7.3, and 4.10.8. The Markdown library allows catastr... |
| CVE-2019-20868 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.11.0. Invite IDs were improperly generated. |
| CVE-2019-20865 | HIGH | 8.8 | 0.5% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.12.0, 5.11.1, 5.10.2, 5.9.2, and 4.10.10. The login page allows CS... |
| CVE-2019-20864 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Plugins before 5.13.0. The GitHub plugin allows an attacker to attach his Mattermo... |
| CVE-2019-20863 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Incoming webhook creation is not properly restricted. |
| CVE-2019-20862 | HIGH | 7.5 | 0.9% | Jun 19, 2020 | An issue was discovered in Mattermost Server before 5.13.0. Non-members may fetch a team's slash commands. |
| CVE-2019-20861 | HIGH | 8.8 | 1.7% | Jun 19, 2020 | An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a craf... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now