2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10487 | CRITICAL | 9.8 | 0.9% | Dec 18, 2019 | Buffer over read can happen while parsing SMS OTA messages at transport layer if network sends un-intended values in Sna... |
| CVE-2019-19846 | CRITICAL | 9.8 | 1.7% | Dec 18, 2019 | In Joomla! before 3.9.14, the lack of validation of configuration parameters used in SQL queries caused various SQL inje... |
| CVE-2019-18257 | CRITICAL | 9.8 | 2.8% | Dec 17, 2019 | In Advantech DiagAnywhere Server, Versions 3.07.11 and prior, multiple stack-based buffer overflow vulnerabilities exist... |
| CVE-2019-19634 | CRITICAL | 9.8 | 4.2% | Dec 17, 2019 | class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! ... |
| CVE-2019-18956 | CRITICAL | 9.8 | 5.8% | Dec 17, 2019 | Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpa... |
| CVE-2019-19826 | CRITICAL | 9.8 | 1.8% | Dec 16, 2019 | The Views Dynamic Fields module through 7.x-1.0-alpha4 for Drupal makes insecure unserialize calls in handlers/views_han... |
| CVE-2019-16778 | CRITICAL | 9.8 | 0.8% | Dec 16, 2019 | In TensorFlow before 1.15, a heap buffer overflow in UnsortedSegmentSum can be produced when the Index template argument... |
| CVE-2019-18269 | CRITICAL | 9.8 | 1.0% | Dec 16, 2019 | Omron’s CS and CJ series PLCs have an unrestricted externally accessible lock vulnerability. |
| CVE-2019-18261 | CRITICAL | 9.8 | 1.3% | Dec 16, 2019 | In Omron PLC CS series, all versions, Omron PLC CJ series, all versions, and Omron PLC NJ series, all versions, the soft... |
| CVE-2019-18259 | CRITICAL | 9.8 | 2.1% | Dec 16, 2019 | In Omron PLC CJ series, all versions and Omron PLC CS series, all versions, an attacker could spoof arbitrary messages o... |
| CVE-2019-18830 | CRITICAL | 9.8 | 4.3% | Dec 16, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 allow OS Command Injection. The embedded 'dongle_bridge' progra... |
| CVE-2019-18826 | CRITICAL | 9.8 | 0.7% | Dec 16, 2019 | Barco ClickShare Button R9861500D01 devices before 1.9.0 have Improper Following of a Certificate's Chain of Trust. The ... |
| CVE-2019-17364 | CRITICAL | 9.8 | 3.6% | Dec 13, 2019 | The processCommandUploadLog() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allow... |
| CVE-2019-16737 | CRITICAL | 9.8 | 3.6% | Dec 13, 2019 | The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows r... |
| CVE-2019-16736 | CRITICAL | 9.8 | 3.4% | Dec 13, 2019 | A stack-based buffer overflow in processCommandUploadSnapshot in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and P... |
| CVE-2019-16735 | CRITICAL | 9.8 | 3.4% | Dec 13, 2019 | A stack-based buffer overflow in processCommandUploadLog in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk... |
| CVE-2019-16734 | CRITICAL | 9.8 | 3.3% | Dec 13, 2019 | Use of default credentials for the TELNET server in Petwant PF-103 firmware 4.3.2.50 and Petalk AI 3.2.2.30 allows remot... |
| CVE-2019-16733 | CRITICAL | 9.8 | 3.6% | Dec 13, 2019 | processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attacke... |
| CVE-2019-16730 | CRITICAL | 9.8 | 3.7% | Dec 13, 2019 | processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attack... |
| CVE-2019-19790 | CRITICAL | 9.8 | 3.0% | Dec 13, 2019 | Path traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with exte... |
| CVE-2019-18802 | CRITICAL | 9.8 | 2.5% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send an HTTP header (such as Host) with whitespa... |
| CVE-2019-18801 | CRITICAL | 9.8 | 2.5% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. An untrusted remote client may send HTTP/2 requests that write to the heap outs... |
| CVE-2019-19782 | CRITICAL | 9.8 | 3.2% | Dec 13, 2019 | The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server. |
| CVE-2019-16774 | CRITICAL | 9.8 | 1.2% | Dec 12, 2019 | In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. |
| CVE-2019-3951 | CRITICAL | 9.8 | 3.6% | Dec 12, 2019 | Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now