2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9531 | CRITICAL | 9.8 | 2.5% | Oct 10, 2019 | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454... |
| CVE-2019-9530 | MEDIUM | 5.5 | 0.4% | Oct 10, 2019 | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and ... |
| CVE-2019-9529 | MEDIUM | 5.5 | 0.3% | Oct 10, 2019 | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This cou... |
| CVE-2019-15051 | HIGH | 8.8 | 3.3% | Oct 10, 2019 | An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to co... |
| CVE-2019-11528 | HIGH | 7.5 | 1.2% | Oct 10, 2019 | An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable. |
| CVE-2019-11527 | HIGH | 8.8 | 3.5% | Oct 10, 2019 | An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously... |
| CVE-2019-14810 | MEDIUM | 5.9 | 0.7% | Oct 10, 2019 | A vulnerability has been found in the implementation of the Label Distribution Protocol (LDP) protocol in EOS. Under rac... |
| CVE-2019-11526 | CRITICAL | 9.8 | 2.0% | Oct 10, 2019 | An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable t... |
| CVE-2019-17455 | CRITICAL | 9.8 | 3.1% | Oct 10, 2019 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthRespon... |
| CVE-2019-5535 | MEDIUM | 4.7 | 0.5% | Oct 10, 2019 | VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6... |
| CVE-2019-5527 | HIGH | 8.8 | 0.3% | Oct 10, 2019 | ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. V... |
| CVE-2019-17454 | MEDIUM | 6.5 | 1.2% | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom... |
| CVE-2019-17453 | MEDIUM | 6.5 | 1.2% | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP... |
| CVE-2019-17452 | MEDIUM | 6.5 | 1.1% | Oct 10, 2019 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to... |
| CVE-2019-17451 | MEDIUM | 6.5 | 2.4% | Oct 10, 2019 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. I... |
| CVE-2019-17450 | MEDIUM | 6.5 | 2.8% | Oct 10, 2019 | find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binut... |
| CVE-2019-17449 | MEDIUM | 6.7 | 0.4% | Oct 10, 2019 | Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerabil... |
| CVE-2019-17320 | CRITICAL | 9.8 | 2.2% | Oct 10, 2019 | NetSarang XFTP Client 6.0149 and earlier version contains a buffer overflow vulnerability caused by improper boundary ch... |
| CVE-2019-4265 | LOW | 2.4 | 0.4% | Oct 10, 2019 | IBM Maximo Anywhere 7.6.0, 7.6.1, 7.6.2, and 7.6.3 does not have device root detection which could result in an attacker... |
| CVE-2019-1378 | HIGH | 7.8 | 1.2% | Oct 10, 2019 | An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locall... |
| CVE-2019-1376 | MEDIUM | 6.5 | 5.0% | Oct 10, 2019 | An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when it improperly enfor... |
| CVE-2019-1375 | MEDIUM | 5.4 | 1.5% | Oct 10, 2019 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a speci... |
| CVE-2019-1372 | CRITICAL | 10 | 17.8% | Oct 10, 2019 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length o... |
| CVE-2019-1371 | HIGH | 7.5 | 7.1% | Oct 10, 2019 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet... |
| CVE-2019-1369 | MEDIUM | 5.5 | 2.0% | Oct 10, 2019 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now