2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18184 | CRITICAL | 9.8 | 8.0% | Nov 27, 2019 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. |
| CVE-2019-10220 | HIGH | 8.8 | 5.1% | Nov 27, 2019 | Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists. |
| CVE-2019-19308 | MEDIUM | 5.5 | 0.9% | Nov 27, 2019 | In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing ... |
| CVE-2019-15300 | HIGH | 8.8 | 2.0% | Nov 27, 2019 | A problem was found in Centreon Web through 19.04.3. An authenticated SQL injection is present in the page include/Admin... |
| CVE-2019-15298 | HIGH | 8.8 | 26.6% | Nov 27, 2019 | A problem was found in Centreon Web through 19.04.3. An authenticated command injection is present in the page include/c... |
| CVE-2019-14812 | HIGH | 7.8 | 2.5% | Nov 27, 2019 | A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly... |
| CVE-2019-13936 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-13935 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-13934 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-10216 | HIGH | 7.8 | 2.3% | Nov 27, 2019 | In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scr... |
| CVE-2019-14896 | CRITICAL | 9.8 | 8.7% | Nov 27, 2019 | A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr... |
| CVE-2019-14867 | HIGH | 8.8 | 6.3% | Nov 27, 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ... |
| CVE-2019-10195 | MEDIUM | 6.5 | 1.4% | Nov 27, 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ... |
| CVE-2019-17590 | HIGH | 8.8 | 0.6% | Nov 26, 2019 | The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it al... |
| CVE-2019-17392 | CRITICAL | 9.8 | 1.1% | Nov 26, 2019 | Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is... |
| CVE-2019-16388 | MEDIUM | 4.3 | 0.7% | Nov 26, 2019 | PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAle... |
| CVE-2019-16387 | HIGH | 8.1 | 1.0% | Nov 26, 2019 | PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li... |
| CVE-2019-16386 | MEDIUM | 4.3 | 0.8% | Nov 26, 2019 | PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivi... |
| CVE-2019-16255 | HIGH | 8.1 | 4.2% | Nov 26, 2019 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "c... |
| CVE-2019-16254 | MEDIUM | 5.3 | 4.6% | Nov 26, 2019 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBr... |
| CVE-2019-16201 | HIGH | 7.5 | 5.1% | Nov 26, 2019 | WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expressi... |
| CVE-2019-16195 | MEDIUM | 6.1 | 1.3% | Nov 26, 2019 | Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields. |
| CVE-2019-18679 | HIGH | 7.5 | 41.0% | Nov 26, 2019 | An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to in... |
| CVE-2019-18678 | MEDIUM | 5.3 | 10.9% | Nov 26, 2019 | An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend ... |
| CVE-2019-18677 | MEDIUM | 6.1 | 7.2% | Nov 26, 2019 | An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended ch... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now