2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12759 | HIGH | 7.8 | 0.5% | Nov 15, 2019 | Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 ... |
| CVE-2019-12758 | MEDIUM | 6.7 | 0.7% | Nov 15, 2019 | Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which m... |
| CVE-2019-12757 | HIGH | 7.8 | 0.4% | Nov 15, 2019 | Symantec Endpoint Protection (SEP), prior to 14.2 RU2 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Ed... |
| CVE-2019-12756 | LOW | 2.3 | 0.3% | Nov 15, 2019 | Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability w... |
| CVE-2019-14345 | CRITICAL | 9.8 | 2.0% | Nov 15, 2019 | TemaTres 3.0 allows remote unprivileged users to create an administrator account |
| CVE-2019-14343 | MEDIUM | 5.4 | 0.9% | Nov 15, 2019 | TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI. |
| CVE-2019-14869 | HIGH | 8.8 | 3.4% | Nov 15, 2019 | A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not prope... |
| CVE-2019-18987 | MEDIUM | 5.3 | 1.1% | Nov 15, 2019 | An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accid... |
| CVE-2019-18986 | HIGH | 7.5 | 1.2% | Nov 15, 2019 | Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality... |
| CVE-2019-18985 | CRITICAL | 9.8 | 1.4% | Nov 15, 2019 | Pimcore before 6.2.2 lacks brute force protection for the 2FA token. |
| CVE-2019-18982 | MEDIUM | 6.1 | 1.1% | Nov 15, 2019 | bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Lo... |
| CVE-2019-18981 | CRITICAL | 9.8 | 1.4% | Nov 15, 2019 | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notificatio... |
| CVE-2019-18928 | CRITICAL | 9.8 | 2.4% | Nov 15, 2019 | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpre... |
| CVE-2019-11931 | HIGH | 7.8 | 1.3% | Nov 14, 2019 | A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user.... |
| CVE-2019-18980 | HIGH | 7.5 | 0.4% | Nov 14, 2019 | On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users ... |
| CVE-2019-18978 | MEDIUM | 5.3 | 2.5% | Nov 14, 2019 | An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory t... |
| CVE-2019-18651 | MEDIUM | 6.5 | 0.7% | Nov 14, 2019 | A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote at... |
| CVE-2019-17391 | MEDIUM | 4.6 | 0.2% | Nov 14, 2019 | An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in ... |
| CVE-2019-15804 | HIGH | 7.5 | 0.9% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI proc... |
| CVE-2019-15803 | CRITICAL | 9.1 | 1.3% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of... |
| CVE-2019-15802 | MEDIUM | 5.9 | 1.5% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts pa... |
| CVE-2019-15801 | HIGH | 7.5 | 1.5% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypt... |
| CVE-2019-15800 | CRITICAL | 9.8 | 3.9% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in ... |
| CVE-2019-15799 | HIGH | 8.8 | 2.3% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the w... |
| CVE-2019-14678 | CRITICAL | 10 | 3.0% | Nov 14, 2019 | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now