2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14910 | CRITICAL | 9.8 | 1.1% | Dec 5, 2019 | A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used in... |
| CVE-2019-19317 | CRITICAL | 9.8 | 4.3% | Dec 5, 2019 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which al... |
| CVE-2019-19589 | CRITICAL | 9.8 | 1.8% | Dec 5, 2019 | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid... |
| CVE-2019-19521 | CRITICAL | 9.8 | 2.7% | Dec 5, 2019 | libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiu... |
| CVE-2019-19228 | CRITICAL | 9.8 | 1.9% | Dec 4, 2019 | Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password f... |
| CVE-2019-19576 | CRITICAL | 9.8 | 26.2% | Dec 4, 2019 | class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an... |
| CVE-2019-17556 | CRITICAL | 9.8 | 3.6% | Dec 4, 2019 | Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and... |
| CVE-2019-11940 | CRITICAL | 9.8 | 1.4% | Dec 4, 2019 | In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations... |
| CVE-2019-11936 | CRITICAL | 9.8 | 1.5% | Dec 4, 2019 | Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue a... |
| CVE-2019-11935 | CRITICAL | 9.8 | 1.5% | Dec 4, 2019 | Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This iss... |
| CVE-2019-11934 | CRITICAL | 9.8 | 1.7% | Dec 4, 2019 | Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly... |
| CVE-2019-11930 | CRITICAL | 9.8 | 3.2% | Dec 4, 2019 | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. Th... |
| CVE-2019-5096 | CRITICAL | 9.8 | 70.8% | Dec 3, 2019 | An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base Go... |
| CVE-2019-19459 | CRITICAL | 9.8 | 3.5% | Dec 3, 2019 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as... |
| CVE-2019-16885 | CRITICAL | 9.8 | 4.6% | Dec 3, 2019 | In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP obj... |
| CVE-2019-19021 | CRITICAL | 9.8 | 1.4% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in... |
| CVE-2019-19015 | CRITICAL | 9.8 | 3.3% | Dec 2, 2019 | An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically exposed to all users) all... |
| CVE-2019-12518 | CRITICAL | 9.8 | 50.7% | Dec 2, 2019 | Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability. |
| CVE-2019-12503 | CRITICAL | 9.8 | 2.0% | Dec 2, 2019 | Due to unencrypted and unauthenticated data communication, the wireless barcode scanner Inateck BCST-60 is prone to keys... |
| CVE-2019-12394 | CRITICAL | 9.8 | 2.1% | Dec 2, 2019 | Anviz access control devices allow unverified password change which allows remote attackers to change the administrator ... |
| CVE-2019-12392 | CRITICAL | 9.8 | 1.9% | Dec 2, 2019 | Anviz access control devices allow remote attackers to issue commands without a password. |
| CVE-2019-19502 | CRITICAL | 9.8 | 1.9% | Dec 2, 2019 | Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated u... |
| CVE-2019-19245 | CRITICAL | 9.8 | 7.9% | Dec 2, 2019 | NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[use... |
| CVE-2019-19492 | CRITICAL | 9.8 | 29.0% | Dec 2, 2019 | FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml. |
| CVE-2019-15631 | CRITICAL | 9.8 | 2.3% | Dec 2, 2019 | Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now