2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18345 | CRITICAL | 9.3 | 2.2% | Dec 12, 2019 | A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a use... |
| CVE-2019-16246 | CRITICAL | 9.8 | 3.3% | Dec 12, 2019 | Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to... |
| CVE-2019-15936 | CRITICAL | 9.8 | 2.4% | Dec 12, 2019 | Intesync Solismed 3.3sp allows Insecure File Upload. |
| CVE-2019-15933 | CRITICAL | 9.8 | 2.0% | Dec 12, 2019 | Intesync Solismed 3.3sp has SQL Injection. |
| CVE-2019-15932 | CRITICAL | 9.8 | 2.3% | Dec 12, 2019 | Intesync Solismed 3.3sp has Incorrect Access Control. |
| CVE-2019-15931 | CRITICAL | 9.8 | 2.7% | Dec 12, 2019 | Intesync Solismed 3.3sp allows Directory Traversal, a different vulnerability than CVE-2019-16246. |
| CVE-2019-2320 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapd... |
| CVE-2019-10559 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Accessing data buffer beyond the available data while parsing ogg clip can lead to null-pointer dereference and then mem... |
| CVE-2019-10511 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Possibility of memory overflow while decoding GSNDCP compressed mode PDU in Snapdragon Auto, Snapdragon Compute, Snapdra... |
| CVE-2019-10493 | CRITICAL | 9.8 | 0.9% | Dec 12, 2019 | Position determination accuracy may be degraded due to wrongly decoded information in Snapdragon Auto, Snapdragon Comput... |
| CVE-2019-19740 | CRITICAL | 9.8 | 5.8% | Dec 12, 2019 | Octeth Oempro 4.7 and 4.8 allow SQL injection. The parameter CampaignID in Campaign.Get is vulnerable. |
| CVE-2019-5093 | CRITICAL | 9.8 | 2.5% | Dec 12, 2019 | An exploitable code execution vulnerability exists in the DICOM network response functionality of LEADTOOLS libltdic.so ... |
| CVE-2019-5085 | CRITICAL | 9.8 | 3.4% | Dec 12, 2019 | An exploitable code execution vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltdic.so, v... |
| CVE-2019-10694 | CRITICAL | 9.8 | 1.1% | Dec 12, 2019 | The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the ins... |
| CVE-2019-3989 | CRITICAL | 9.8 | 3.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-0403 | CRITICAL | 9.8 | 2.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, allows an attacker to input commands into the CSV files, which will be executed whe... |
| CVE-2019-19374 | CRITICAL | 9.1 | 3.4% | Dec 11, 2019 | An issue was discovered in core/assets/form/form_question_types/form_question_type_file_upload/form_question_type_file_u... |
| CVE-2019-19725 | CRITICAL | 9.8 | 2.8% | Dec 11, 2019 | sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c. |
| CVE-2019-19649 | CRITICAL | 9.8 | 9.5% | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13620 allows a remote unauthenticated SQL injection via the SyncEventServl... |
| CVE-2019-18960 | CRITICAL | 9.8 | 3.3% | Dec 11, 2019 | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitab... |
| CVE-2019-18935 | CRITICAL | 9.8 | 99.7% | Dec 11, 2019 | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp... |
| CVE-2019-17270 | CRITICAL | 9.8 | 58.9% | Dec 10, 2019 | Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi... |
| CVE-2019-4521 | CRITICAL | 9.8 | 2.6% | Dec 10, 2019 | Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could ... |
| CVE-2019-4244 | CRITICAL | 9.1 | 2.1% | Dec 10, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestri... |
| CVE-2019-4621 | CRITICAL | 9.8 | 1.6% | Dec 9, 2019 | IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account tha... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now