2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8162HIGH8.1Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8161CRITICAL9.8Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8160MEDIUM6.1Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-8064MEDIUM4.3Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier, ...
CVE-2019-6476HIGH7.5A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder re...
CVE-2019-6475HIGH7.5Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by other servers. A mirror zo...
CVE-2019-18192HIGH7.8GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user...
CVE-2019-15066CRITICAL9.8An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execu...
CVE-2019-15065HIGH7.5A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific c...
CVE-2019-15064CRITICAL9.8HiNet GPON firmware version < I040GWR190731 allows an attacker login to device without any authentication.
CVE-2019-13412HIGH7.5A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific c...
CVE-2019-13410HIGH7.5TOPMeeting before version 8.8 (2019/08/19) shows attendees account and password in front end page that allows an attacke...
CVE-2019-13409CRITICAL9.8A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union ...
CVE-2019-8071CRITICAL9.8Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could...
CVE-2019-17120MEDIUM6.1A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow...
CVE-2019-17119HIGH8.8Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticate...
CVE-2019-15627HIGH7.1Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w...
CVE-2019-15626HIGH7.5The Deep Security Manager application (Versions 10.0, 11.0 and 12.0), when configured in a certain way, may transmit ini...
CVE-2019-13657HIGH8.8CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that...
CVE-2019-12611MEDIUM4.4An issue was discovered in Bitdefender BOX firmware versions before 2.1.37.37-34 that affects the general reliability of...
CVE-2019-10752CRITICAL9.8Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helpe...
CVE-2019-17631CRITICAL9.1From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are...
CVE-2019-17118HIGH8.8A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user ...
CVE-2019-17117HIGH8.8A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authentica...
CVE-2019-17116MEDIUM6.1A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now