2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17376 | MEDIUM | 6.1 | 0.5% | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521). |
| CVE-2019-17375 | HIGH | 8.8 | 1.1% | Oct 9, 2019 | cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517). |
| CVE-2019-17128 | HIGH | 7.5 | 1.8% | Oct 9, 2019 | Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters a... |
| CVE-2019-17124 | CRITICAL | 9.8 | 23.1% | Oct 9, 2019 | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. |
| CVE-2019-15859 | CRITICAL | 9.8 | 34.1% | Oct 9, 2019 | Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get f... |
| CVE-2019-15226 | HIGH | 7.5 | 65.4% | Oct 9, 2019 | Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the to... |
| CVE-2019-14808 | MEDIUM | 6.8 | 1.3% | Oct 9, 2019 | An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without ... |
| CVE-2019-13529 | HIGH | 8.8 | 2.2% | Oct 9, 2019 | An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action... |
| CVE-2019-11341 | MEDIUM | 4.6 | 0.2% | Oct 9, 2019 | On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowl... |
| CVE-2019-11212 | MEDIUM | 5.4 | 0.7% | Oct 9, 2019 | The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an... |
| CVE-2019-17382 | CRITICAL | 9.1 | 54.1% | Oct 9, 2019 | An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass ... |
| CVE-2019-17373 | CRITICAL | 9.8 | 1.5% | Oct 9, 2019 | Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, s... |
| CVE-2019-17372 | HIGH | 8.1 | 1.7% | Oct 9, 2019 | Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanCha... |
| CVE-2019-17371 | MEDIUM | 6.5 | 1.5% | Oct 9, 2019 | gif2png 2.5.13 has a memory leak in the writefile function. |
| CVE-2019-17370 | HIGH | 7.2 | 2.1% | Oct 9, 2019 | OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT st... |
| CVE-2019-17354 | CRITICAL | 9.4 | 1.4% | Oct 9, 2019 | wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication,... |
| CVE-2019-17353 | HIGH | 8.2 | 3.0% | Oct 9, 2019 | An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly wi... |
| CVE-2019-15719 | HIGH | 8 | 2.0% | Oct 9, 2019 | Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pb... |
| CVE-2019-13051 | HIGH | 8.8 | 12.5% | Oct 9, 2019 | Pi-Hole 4.3 allows Command Injection. |
| CVE-2019-17369 | MEDIUM | 6.5 | 0.5% | Oct 9, 2019 | OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group accoun... |
| CVE-2019-17368 | MEDIUM | 6.1 | 0.8% | Oct 9, 2019 | S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter. |
| CVE-2019-17362 | CRITICAL | 9.1 | 3.2% | Oct 9, 2019 | In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detec... |
| CVE-2019-3980 | CRITICAL | 9.8 | 5.2% | Oct 8, 2019 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to... |
| CVE-2019-10757 | CRITICAL | 9.8 | 1.2% | Oct 8, 2019 | knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of th... |
| CVE-2019-0381 | MEDIUM | 5.5 | 0.3% | Oct 8, 2019 | A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before ve... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now