2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18663 | CRITICAL | 9.8 | 1.4% | Nov 4, 2019 | A SQL injection vulnerability in a /login/forgot1 POST request in ARP-GUARD 4.0.0-5 allows unauthenticated remote attack... |
| CVE-2019-18178 | HIGH | 7.5 | 0.9% | Nov 4, 2019 | Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file... |
| CVE-2019-17210 | HIGH | 7.5 | 1.0% | Nov 4, 2019 | A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString()... |
| CVE-2019-13497 | MEDIUM | 6.5 | 0.7% | Nov 4, 2019 | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows CSRF for logout requests. |
| CVE-2019-13496 | HIGH | 8.1 | 0.8% | Nov 4, 2019 | One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a man in the middle, the... |
| CVE-2019-18684 | HIGH | 7 | 0.3% | Nov 4, 2019 | Sudo through 1.8.29 allows local users to escalate to root if they have write access to file descriptor 3 of the sudo pr... |
| CVE-2019-18683 | HIGH | 7 | 1.0% | Nov 4, 2019 | An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privile... |
| CVE-2019-18680 | HIGH | 7.5 | 3.6% | Nov 4, 2019 | An issue was discovered in the Linux kernel 4.4.x before 4.4.195. There is a NULL pointer dereference in rds_tcp_kill_so... |
| CVE-2019-0350 | HIGH | 7.5 | 1.1% | Nov 4, 2019 | SAP HANA Database, versions 1.0, 2.0, allows an unauthorized attacker to send a malformed connection request, which cras... |
| CVE-2019-18673 | MEDIUM | 4.6 | 0.4% | Nov 2, 2019 | On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-ba... |
| CVE-2019-14360 | MEDIUM | 4.6 | 0.4% | Nov 2, 2019 | On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of ... |
| CVE-2019-14358 | MEDIUM | 4.6 | 0.4% | Nov 2, 2019 | On Archos Safe-T devices, a side channel for the row-based OLED display was found. The power consumption of each row-bas... |
| CVE-2019-18668 | MEDIUM | 6.5 | 1.8% | Nov 2, 2019 | An issue was discovered in the Currency Switcher addon before 2.11.2 for WooCommerce if a user provides a currency that ... |
| CVE-2019-18667 | MEDIUM | 6.1 | 4.0% | Nov 2, 2019 | /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a use... |
| CVE-2019-18665 | HIGH | 7.5 | 14.9% | Nov 2, 2019 | The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. |
| CVE-2019-18664 | MEDIUM | 5.4 | 0.6% | Nov 2, 2019 | The Log module in SECUDOS DOMOS before 5.6 allows XSS. |
| CVE-2019-18662 | CRITICAL | 9.8 | 2.3% | Nov 2, 2019 | An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plu... |
| CVE-2019-18661 | HIGH | 7.5 | 1.5% | Nov 2, 2019 | Fastweb FASTGate 1.0.1b devices allow partial authentication bypass by changing a certain check_pwd return value from 0 ... |
| CVE-2019-18659 | MEDIUM | 5.3 | 1.0% | Nov 2, 2019 | The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic... |
| CVE-2019-6470 | HIGH | 7.5 | 8.8% | Nov 1, 2019 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 m... |
| CVE-2019-18654 | MEDIUM | 6.1 | 0.9% | Nov 1, 2019 | A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in ... |
| CVE-2019-18653 | MEDIUM | 6.1 | 0.9% | Nov 1, 2019 | A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 b... |
| CVE-2019-12752 | MEDIUM | 6.1 | 0.4% | Nov 1, 2019 | The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which coul... |
| CVE-2019-6658 | MEDIUM | 4.3 | 0.7% | Nov 1, 2019 | On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration... |
| CVE-2019-6657 | MEDIUM | 6.1 | 0.6% | Nov 1, 2019 | On BIG-IP 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, a reflected cross-site scripting (XSS) vulnerability exis... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now