2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5850 | CRITICAL | 9.6 | 1.0% | Nov 25, 2019 | Use after free in offline mode in Google Chrome prior to 76.0.3809.87 allowed a remote attacker who had compromised the ... |
| CVE-2019-18622 | CRITICAL | 9.8 | 2.6% | Nov 22, 2019 | An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection... |
| CVE-2019-13566 | CRITICAL | 9.8 | 3.1% | Nov 22, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3... |
| CVE-2019-18933 | CRITICAL | 9.8 | 1.4% | Nov 21, 2019 | In Zulip Server versions from 1.7.0 to before 2.0.7, a bug in the new user signup process meant that users who registere... |
| CVE-2019-18889 | CRITICAL | 9.8 | 33.2% | Nov 21, 2019 | An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing cert... |
| CVE-2019-11325 | CRITICAL | 9.8 | 3.4% | Nov 21, 2019 | An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes str... |
| CVE-2019-19033 | CRITICAL | 9.8 | 3.3% | Nov 21, 2019 | Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges v... |
| CVE-2019-19006 | CRITICAL | 9.8 | 35.8% | Nov 21, 2019 | Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control. |
| CVE-2019-18349 | CRITICAL | 9.8 | 2.4% | Nov 21, 2019 | HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp. |
| CVE-2019-5509 | CRITICAL | 9.8 | 2.3% | Nov 21, 2019 | ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerabil... |
| CVE-2019-2303 | CRITICAL | 9.8 | 0.7% | Nov 21, 2019 | SNDCP module may access array out side its boundary when it receives malformed XID message. in Snapdragon Auto, Snapdrag... |
| CVE-2019-2289 | CRITICAL | 9.8 | 0.6% | Nov 21, 2019 | Lack of integrity check allows MODEM to accept any NAS messages which can result into authentication bypass of NAS in Sn... |
| CVE-2019-2271 | CRITICAL | 9.8 | 1.1% | Nov 21, 2019 | Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values i... |
| CVE-2019-2268 | CRITICAL | 9.8 | 0.7% | Nov 21, 2019 | Possible OOB read issue in P2P action frames while handling WLAN management frame in Snapdragon Auto, Snapdragon Consume... |
| CVE-2019-16541 | CRITICAL | 9.9 | 1.6% | Nov 21, 2019 | Jenkins JIRA Plugin 3.0.10 and earlier does not declare the correct (folder) scope for per-folder Jira site definitions,... |
| CVE-2019-16340 | CRITICAL | 9.8 | 19.3% | Nov 21, 2019 | Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for ... |
| CVE-2019-10627 | CRITICAL | 9.8 | 1.4% | Nov 21, 2019 | Integer overflow to buffer overflow vulnerability in PostScript image handling code used by the PostScript- and PDF-comp... |
| CVE-2019-18858 | CRITICAL | 9.8 | 2.0% | Nov 20, 2019 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. |
| CVE-2019-5541 | CRITICAL | 9.1 | 1.4% | Nov 20, 2019 | VMware Workstation (15.x before 15.5.1) and Fusion (11.x before 11.5.1) contain an out-of-bounds write vulnerability in ... |
| CVE-2019-10765 | CRITICAL | 9.8 | 1.7% | Nov 20, 2019 | iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. |
| CVE-2019-10766 | CRITICAL | 9.8 | 1.5% | Nov 19, 2019 | Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sa... |
| CVE-2019-12409 | CRITICAL | 9.8 | 21.9% | Nov 18, 2019 | The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration opt... |
| CVE-2019-12271 | CRITICAL | 9.8 | 2.0% | Nov 18, 2019 | Sandline Centraleyezer (On Premises) allows unrestricted File Upload with a dangerous type, because the feature of addin... |
| CVE-2019-19113 | CRITICAL | 9.8 | 1.8% | Nov 18, 2019 | main/resources/mapper/NewBeeMallGoodsMapper.xml in newbee-mall (aka New Bee) before 2019-10-23 allows search?goodsCatego... |
| CVE-2019-17058 | CRITICAL | 9.1 | 1.9% | Nov 18, 2019 | Footy Tipping Software AFL Web Edition 2019 allows arbitrary file upload and resultant remote code execution because a w... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now