2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17600 | CRITICAL | 9.8 | 1.2% | Oct 15, 2019 | Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user i... |
| CVE-2019-17195 | CRITICAL | 9.8 | 11.0% | Oct 15, 2019 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in ... |
| CVE-2019-12944 | HIGH | 7.5 | 1.0% | Oct 15, 2019 | Glue Smart Lock 2.7.8 devices do not properly block guest access in certain situations where the network connection is u... |
| CVE-2019-17223 | MEDIUM | 6.1 | 1.1% | Oct 15, 2019 | There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. |
| CVE-2019-17595 | MEDIUM | 5.4 | 2.0% | Oct 14, 2019 | There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses... |
| CVE-2019-17594 | MEDIUM | 5.3 | 0.5% | Oct 14, 2019 | There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in nc... |
| CVE-2019-17593 | HIGH | 8.8 | 0.5% | Oct 14, 2019 | JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator. |
| CVE-2019-17592 | HIGH | 7.5 | 2.3% | Oct 14, 2019 | The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() funct... |
| CVE-2019-14823 | HIGH | 7.4 | 0.9% | Oct 14, 2019 | A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4... |
| CVE-2019-14737 | HIGH | 7.8 | 1.7% | Oct 14, 2019 | Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. |
| CVE-2019-3767 | HIGH | 8.2 | 0.2% | Oct 14, 2019 | Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability. Dell ImageAssist stores some ... |
| CVE-2019-16282 | MEDIUM | 5.4 | 0.6% | Oct 14, 2019 | In NCH Express Invoice v7.12, persistent cross site scripting (XSS) exists via the Invoices/Items/Customers/Quotes input... |
| CVE-2019-12941 | CRITICAL | 9.8 | 2.4% | Oct 14, 2019 | AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary at... |
| CVE-2019-17044 | HIGH | 7.8 | 0.4% | Oct 14, 2019 | An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could all... |
| CVE-2019-17043 | HIGH | 7.8 | 0.4% | Oct 14, 2019 | An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary coul... |
| CVE-2019-16279 | HIGH | 7.5 | 19.8% | Oct 14, 2019 | A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of ser... |
| CVE-2019-16278 | CRITICAL | 9.8 | 99.1% | Oct 14, 2019 | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co... |
| CVE-2019-14227 | MEDIUM | 6.1 | 1.0% | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows XSS. |
| CVE-2019-14226 | HIGH | 8.1 | 1.2% | Oct 14, 2019 | OX App Suite through 7.10.2 has Insecure Permissions. |
| CVE-2019-14225 | MEDIUM | 5.4 | 0.7% | Oct 14, 2019 | OX App Suite 7.10.1 and 7.10.2 allows SSRF. |
| CVE-2019-17583 | HIGH | 7.5 | 1.3% | Oct 14, 2019 | idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many ... |
| CVE-2019-17580 | CRITICAL | 9.8 | 1.1% | Oct 14, 2019 | tonyy dormsystem through 1.3 allows SQL Injection in admin.php. |
| CVE-2019-17511 | HIGH | 7.5 | 1.6% | Oct 14, 2019 | There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can g... |
| CVE-2019-16519 | HIGH | 7.8 | 0.3% | Oct 14, 2019 | ESET Cyber Security 6.7.900.0 for macOS allows a local attacker to execute unauthorized commands as root by abusing an u... |
| CVE-2019-9745 | HIGH | 7.8 | 0.5% | Oct 14, 2019 | CloudCTI HIP Integrator Recognition Configuration Tool allows privilege escalation via its EXQUISE integration. This too... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now