2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12759HIGH7.8Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 ...
CVE-2019-12758MEDIUM6.7Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which m...
CVE-2019-12757HIGH7.8Symantec Endpoint Protection (SEP), prior to 14.2 RU2 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Ed...
CVE-2019-12756LOW2.3Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability w...
CVE-2019-14345CRITICAL9.8TemaTres 3.0 allows remote unprivileged users to create an administrator account
CVE-2019-14343MEDIUM5.4TemaTres 3.0 has stored XSS via the value parameter to the vocab/admin.php?vocabulario_id=list URI.
CVE-2019-14869HIGH8.8A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not prope...
CVE-2019-18987MEDIUM5.3An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accid...
CVE-2019-18986HIGH7.5Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality...
CVE-2019-18985CRITICAL9.8Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
CVE-2019-18982MEDIUM6.1bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Lo...
CVE-2019-18981CRITICAL9.8Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notificatio...
CVE-2019-18928CRITICAL9.8Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpre...
CVE-2019-11931HIGH7.8A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user....
CVE-2019-18980HIGH7.5On Signify Philips Taolight Smart Wi-Fi Wiz Connected LED Bulb 9290022656 devices, an unprotected API lets remote users ...
CVE-2019-18978MEDIUM5.3An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory t...
CVE-2019-18651MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in 3xLogic Infinias Access Control through 6.6.9586.0 allows remote at...
CVE-2019-17391MEDIUM4.6An issue was discovered in the Espressif ESP32 mask ROM code 2016-06-08 0 through 2. Lack of anti-glitch mitigations in ...
CVE-2019-15804HIGH7.5An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. By sending a signal to the CLI proc...
CVE-2019-15803CRITICAL9.1An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of...
CVE-2019-15802MEDIUM5.9An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware hashes and encrypts pa...
CVE-2019-15801HIGH7.5An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. The firmware image contains encrypt...
CVE-2019-15800CRITICAL9.8An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in ...
CVE-2019-15799HIGH8.8An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. User accounts created through the w...
CVE-2019-14678CRITICAL10SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now