2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17107HIGH8.8minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the comman...
CVE-2019-17106MEDIUM6.5In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move late...
CVE-2019-17104HIGH7.5In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft be...
CVE-2019-16929HIGH7.5Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to val...
CVE-2019-16417MEDIUM5.4HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-16416MEDIUM5.4HRworks 3.36.9 allows XSS via the purpose of a travel-expense report.
CVE-2019-14657HIGH8.8Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but...
CVE-2019-14656HIGH8.8Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User acco...
CVE-2019-13336CRITICAL9.8The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication veri...
CVE-2019-17262HIGH7.8XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0.
CVE-2019-17261HIGH7.8XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51.
CVE-2019-17260HIGH7.8MPC-HC through 1.7.13 allows a Read Access Violation on a Block Data Move starting at mpc_hc!memcpy+0x000000000000004e.
CVE-2019-17259HIGH7.8KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee.
CVE-2019-17258HIGH7.8IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000...
CVE-2019-17257MEDIUM5.5IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80.
CVE-2019-17256HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203.
CVE-2019-17255HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at EXR!ReadEXR+0x0000000000010836.
CVE-2019-17254HIGH7.8IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at FORMATS!Read_BadPNG...
CVE-2019-17253HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at JPEG_LS+0x000000000000a6b8.
CVE-2019-17252HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!Read_BadPNG+0x0000000000000115.
CVE-2019-17251HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d43.
CVE-2019-17250HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000042f5.
CVE-2019-17249HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000d57b.
CVE-2019-17248HIGH7.8IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000025b6.
CVE-2019-17247HIGH7.8IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now