2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19012 | CRITICAL | 9.8 | 10.5% | Nov 17, 2019 | An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bo... |
| CVE-2019-19010 | CRITICAL | 9.8 | 1.7% | Nov 16, 2019 | Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivi... |
| CVE-2019-13582 | CRITICAL | 9.8 | 2.2% | Nov 15, 2019 | An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa... |
| CVE-2019-13581 | CRITICAL | 9.8 | 3.4% | Nov 15, 2019 | An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa... |
| CVE-2019-14345 | CRITICAL | 9.8 | 2.0% | Nov 15, 2019 | TemaTres 3.0 allows remote unprivileged users to create an administrator account |
| CVE-2019-18985 | CRITICAL | 9.8 | 1.4% | Nov 15, 2019 | Pimcore before 6.2.2 lacks brute force protection for the 2FA token. |
| CVE-2019-18981 | CRITICAL | 9.8 | 1.4% | Nov 15, 2019 | Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notificatio... |
| CVE-2019-18928 | CRITICAL | 9.8 | 2.4% | Nov 15, 2019 | Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpre... |
| CVE-2019-15803 | CRITICAL | 9.1 | 1.3% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of... |
| CVE-2019-15800 | CRITICAL | 9.8 | 3.9% | Nov 14, 2019 | An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in ... |
| CVE-2019-14678 | CRITICAL | 10 | 3.0% | Nov 14, 2019 | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multi... |
| CVE-2019-18939 | CRITICAL | 9.8 | 40.8% | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution ... |
| CVE-2019-18938 | CRITICAL | 9.8 | 33.8% | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution... |
| CVE-2019-18937 | CRITICAL | 9.8 | 33.8% | Nov 14, 2019 | eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execut... |
| CVE-2019-11171 | CRITICAL | 9.8 | 1.6% | Nov 14, 2019 | Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially en... |
| CVE-2019-11168 | CRITICAL | 9.1 | 1.3% | Nov 14, 2019 | Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user t... |
| CVE-2019-8248 | CRITICAL | 9.8 | 4.0% | Nov 14, 2019 | Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2019-8247 | CRITICAL | 9.8 | 4.0% | Nov 14, 2019 | Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea... |
| CVE-2019-8246 | CRITICAL | 9.8 | 4.6% | Nov 14, 2019 | Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l... |
| CVE-2019-5029 | CRITICAL | 9.8 | 57.1% | Nov 13, 2019 | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7... |
| CVE-2019-18952 | CRITICAL | 9.8 | 45.4% | Nov 13, 2019 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951... |
| CVE-2019-18240 | CRITICAL | 9.8 | 14.0% | Nov 13, 2019 | In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an ... |
| CVE-2019-2205 | CRITICAL | 9.8 | 2.9% | Nov 13, 2019 | In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free.... |
| CVE-2019-2204 | CRITICAL | 9.8 | 1.3% | Nov 13, 2019 | In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This ... |
| CVE-2019-2036 | CRITICAL | 9.8 | 2.0% | Nov 13, 2019 | In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now