2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-20656HIGH8.8Certain NETGEAR devices are affected by a hardcoded password. This affects D6200 before 1.1.00.36, D7000 before 1.0.1.74...
CVE-2019-20655HIGH7.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 a...
CVE-2019-20654HIGH7.5Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4...
CVE-2019-20650HIGH7.5Certain NETGEAR devices are affected by denial of service. This affects R8900 before 1.0.5.2, R9000 before 1.0.5.2, XR50...
CVE-2019-20649HIGH7.5NETGEAR MR1100 devices before 12.06.08.00 are affected by disclosure of sensitive information.
CVE-2019-20643HIGH7.5NETGEAR RAX40 devices before 1.0.3.64 are affected by disclosure of sensitive information.
CVE-2019-20642HIGH8NETGEAR RAX40 devices before 1.0.3.64 are affected by authentication bypass.
CVE-2019-20641HIGH8.8NETGEAR RAX40 devices before 1.0.3.64 are affected by lack of access control at the function level.
CVE-2019-20640HIGH8.8Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D3600...
CVE-2019-2880HIGH8.8Vulnerability in the Oracle Retail Store Inventory Management product of Oracle Retail Applications (component: Security...
CVE-2019-20767HIGH7.2Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor...
CVE-2019-19301HIGH7.5A vulnerability has been identified in SCALANCE X200-4P IRT, SCALANCE X201-3P IRT, SCALANCE X201-3P IRT PRO, SCALANCE X2...
CVE-2019-19300HIGH7.5A vulnerability has been identified in Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200, Development/Evaluation...
CVE-2019-14326HIGH7.8An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) ...
CVE-2019-18822HIGH8.8A privilege escalation vulnerability in ZOOM Call Recording 6.3.1 allows its user account (i.e., the account under which...
CVE-2019-11480HIGH8.1The pc-kernel snap build process hardcoded the --allow-insecure-repositories and --allow-unauthenticated apt options whe...
CVE-2019-13916HIGH8.8An issue was discovered in Cypress (formerly Broadcom) WICED Studio 6.2 CYW20735B1 and CYW20819A1. As a Bluetooth Low En...
CVE-2019-20637HIGH7.5An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does...
CVE-2019-15789HIGH7.8Privilege escalation vulnerability in MicroK8s allows a low privilege user with local access to obtain root access to th...
CVE-2019-17657HIGH7.5An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer ...
CVE-2019-13559HIGH7.8GE Mark VIe Controller is shipped with pre-configured hard-coded credentials that may allow root-user access to the cont...
CVE-2019-13554HIGH8.8GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using g...
CVE-2019-4391HIGH8.2HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
CVE-2019-19699HIGH7.2There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi...
CVE-2019-18904HIGH7.5A Uncontrolled Resource Consumption vulnerability in rmt of SUSE Linux Enterprise High Performance Computing 15-ESPOS, S...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now