2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18609 | CRITICAL | 9.8 | 3.3% | Dec 1, 2019 | An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that... |
| CVE-2019-19391 | CRITICAL | 9.1 | 1.3% | Nov 29, 2019 | In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue th... |
| CVE-2019-14901 | CRITICAL | 9.8 | 16.9% | Nov 29, 2019 | A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri... |
| CVE-2019-14897 | CRITICAL | 9.8 | 2.9% | Nov 29, 2019 | A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An atta... |
| CVE-2019-14895 | CRITICAL | 9.8 | 7.8% | Nov 29, 2019 | A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell ... |
| CVE-2019-18253 | CRITICAL | 10 | 2.0% | Nov 27, 2019 | An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (vers... |
| CVE-2019-6665 | CRITICAL | 9.4 | 1.1% | Nov 27, 2019 | On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow ... |
| CVE-2019-19330 | CRITICAL | 9.8 | 3.9% | Nov 27, 2019 | The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd... |
| CVE-2019-18184 | CRITICAL | 9.8 | 8.0% | Nov 27, 2019 | Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function. |
| CVE-2019-14896 | CRITICAL | 9.8 | 8.7% | Nov 27, 2019 | A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip dr... |
| CVE-2019-17392 | CRITICAL | 9.8 | 1.1% | Nov 26, 2019 | Progress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is... |
| CVE-2019-18580 | CRITICAL | 10 | 4.9% | Nov 26, 2019 | Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerabil... |
| CVE-2019-12526 | CRITICAL | 9.8 | 20.3% | Nov 26, 2019 | An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. W... |
| CVE-2019-12523 | CRITICAL | 9.1 | 4.3% | Nov 26, 2019 | An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTT... |
| CVE-2019-19307 | CRITICAL | 9.8 | 41.4% | Nov 26, 2019 | An integer overflow in parse_mqtt in mongoose.c in Cesanta Mongoose 6.16 allows an attacker to achieve remote DoS (infin... |
| CVE-2019-14842 | CRITICAL | 9.8 | 1.8% | Nov 26, 2019 | Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check... |
| CVE-2019-6675 | CRITICAL | 9.8 | 0.9% | Nov 26, 2019 | BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multip... |
| CVE-2019-12489 | CRITICAL | 9.8 | 6.2% | Nov 26, 2019 | An issue was discovered on Fastweb Askey RTV1907VW 0.00.81_FW_200_Askey 2018-10-02 18:08:18 devices. By using the usb_re... |
| CVE-2019-15958 | CRITICAL | 9.8 | 3.3% | Nov 26, 2019 | A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM)... |
| CVE-2019-18250 | CRITICAL | 9.8 | 1.7% | Nov 26, 2019 | In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable... |
| CVE-2019-19250 | CRITICAL | 9.8 | 1.0% | Nov 25, 2019 | OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js. |
| CVE-2019-19249 | CRITICAL | 9.8 | 1.2% | Nov 25, 2019 | Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations. |
| CVE-2019-18374 | CRITICAL | 9.8 | 1.7% | Nov 25, 2019 | Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypa... |
| CVE-2019-5870 | CRITICAL | 9.6 | 1.4% | Nov 25, 2019 | Use after free in media in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbo... |
| CVE-2019-5866 | CRITICAL | 9.8 | 1.1% | Nov 25, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to potential... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now