2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17107 | HIGH | 8.8 | 3.6% | Oct 8, 2019 | minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the comman... |
| CVE-2019-17106 | MEDIUM | 6.5 | 1.1% | Oct 8, 2019 | In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move late... |
| CVE-2019-17104 | HIGH | 7.5 | 1.9% | Oct 8, 2019 | In Centreon VM through 19.04.3, the cookie configuration within the Apache HTTP Server does not protect against theft be... |
| CVE-2019-16929 | HIGH | 7.5 | 0.9% | Oct 8, 2019 | Auth0 auth0.net before 6.5.4 has Incorrect Access Control because IdentityTokenValidator can be accidentally used to val... |
| CVE-2019-16417 | MEDIUM | 5.4 | 0.7% | Oct 8, 2019 | HRworks FLOW 3.36.9 allows XSS via the purpose of a travel-expense report. |
| CVE-2019-16416 | MEDIUM | 5.4 | 0.7% | Oct 8, 2019 | HRworks 3.36.9 allows XSS via the purpose of a travel-expense report. |
| CVE-2019-14657 | HIGH | 8.8 | 3.7% | Oct 8, 2019 | Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but... |
| CVE-2019-14656 | HIGH | 8.8 | 2.0% | Oct 8, 2019 | Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User acco... |
| CVE-2019-13336 | CRITICAL | 9.8 | 2.9% | Oct 8, 2019 | The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication veri... |
| CVE-2019-17262 | HIGH | 7.8 | 0.4% | Oct 8, 2019 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001fc0. |
| CVE-2019-17261 | HIGH | 7.8 | 0.4% | Oct 8, 2019 | XnView Classic 2.49.1 allows a User Mode Write AV starting at Xwsq+0x0000000000001e51. |
| CVE-2019-17260 | HIGH | 7.8 | 0.4% | Oct 8, 2019 | MPC-HC through 1.7.13 allows a Read Access Violation on a Block Data Move starting at mpc_hc!memcpy+0x000000000000004e. |
| CVE-2019-17259 | HIGH | 7.8 | 0.5% | Oct 8, 2019 | KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee. |
| CVE-2019-17258 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000... |
| CVE-2019-17257 | MEDIUM | 5.5 | 1.3% | Oct 8, 2019 | IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR+0x000000000002af80. |
| CVE-2019-17256 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at DPX!ReadDPX_W+0x0000000000001203. |
| CVE-2019-17255 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at EXR!ReadEXR+0x0000000000010836. |
| CVE-2019-17254 | HIGH | 7.8 | 2.5% | Oct 8, 2019 | IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at FORMATS!Read_BadPNG... |
| CVE-2019-17253 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at JPEG_LS+0x000000000000a6b8. |
| CVE-2019-17252 | HIGH | 7.8 | 2.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!Read_BadPNG+0x0000000000000115. |
| CVE-2019-17251 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at FORMATS!GetPlugInInfo+0x0000000000007d43. |
| CVE-2019-17250 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000042f5. |
| CVE-2019-17249 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x000000000000d57b. |
| CVE-2019-17248 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows a User Mode Write AV starting at WSQ!ReadWSQ+0x00000000000025b6. |
| CVE-2019-17247 | HIGH | 7.8 | 1.5% | Oct 8, 2019 | IrfanView 4.53 allows Data from a Faulting Address to control a subsequent Write Address starting at JPEG_LS+0x000000000... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now