2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19197 | HIGH | 7.8 | 0.6% | Nov 21, 2019 | IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escala... |
| CVE-2019-19191 | HIGH | 7.8 | 0.5% | Nov 21, 2019 | Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlle... |
| CVE-2019-19033 | CRITICAL | 9.8 | 3.3% | Nov 21, 2019 | Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges v... |
| CVE-2019-19006 | CRITICAL | 9.8 | 35.8% | Nov 21, 2019 | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. |
| CVE-2019-18890 | MEDIUM | 6.5 | 4.3% | Nov 21, 2019 | A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected ... |
| CVE-2019-18886 | MEDIUM | 5.3 | 1.6% | Nov 21, 2019 | An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t... |
| CVE-2019-18349 | CRITICAL | 9.8 | 2.4% | Nov 21, 2019 | HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp. |
| CVE-2019-16758 | HIGH | 7.5 | 16.8% | Nov 21, 2019 | In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech... |
| CVE-2019-16406 | HIGH | 7.8 | 0.5% | Nov 21, 2019 | Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual ma... |
| CVE-2019-16405 | HIGH | 7.2 | 27.0% | Nov 21, 2019 | Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code... |
| CVE-2019-15511 | HIGH | 7.8 | 0.7% | Nov 21, 2019 | An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due t... |
| CVE-2019-5072 | HIGH | 7.8 | 1.8% | Nov 21, 2019 | An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Rout... |
| CVE-2019-5071 | HIGH | 7.8 | 1.7% | Nov 21, 2019 | An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Rout... |
| CVE-2019-10767 | HIGH | 7.5 | 2.2% | Nov 21, 2019 | An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent... |
| CVE-2019-6693 | MEDIUM | 6.5 | 5.7% | Nov 21, 2019 | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke... |
| CVE-2019-5509 | CRITICAL | 9.8 | 2.3% | Nov 21, 2019 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerabil... |
| CVE-2019-5087 | HIGH | 8.8 | 3.6% | Nov 21, 2019 | An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm bin... |
| CVE-2019-5086 | HIGH | 8.8 | 3.2% | Nov 21, 2019 | An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm bin... |
| CVE-2019-17650 | HIGH | 7.8 | 0.4% | Nov 21, 2019 | An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root pro... |
| CVE-2019-17272 | HIGH | 7.2 | 1.3% | Nov 21, 2019 | All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully ex... |
| CVE-2019-2339 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Au... |
| CVE-2019-2336 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au... |
| CVE-2019-2335 | HIGH | 7.5 | 0.6% | Nov 21, 2019 | While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Au... |
| CVE-2019-2329 | HIGH | 7.8 | 0.2% | Nov 21, 2019 | Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application.... |
| CVE-2019-2318 | MEDIUM | 5.5 | 0.2% | Nov 21, 2019 | Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now