2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16948 | CRITICAL | 9.8 | 1.3% | Nov 13, 2019 | An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at We... |
| CVE-2019-18839 | CRITICAL | 9 | 5.4% | Nov 13, 2019 | FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attack... |
| CVE-2019-6188 | CRITICAL | 9.8 | 1.3% | Nov 12, 2019 | The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p,... |
| CVE-2019-17330 | CRITICAL | 9.6 | 1.0% | Nov 12, 2019 | The Web server component of TIBCO Software Inc.'s TIBCO EBX contains multiple vulnerabilities that theoretically allow a... |
| CVE-2019-1449 | CRITICAL | 9.8 | 6.4% | Nov 12, 2019 | A security feature bypass vulnerability exists in the way that Office Click-to-Run (C2R) components handle a specially c... |
| CVE-2019-1384 | CRITICAL | 9.9 | 6.1% | Nov 12, 2019 | A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messa... |
| CVE-2019-1373 | CRITICAL | 9.8 | 18.2% | Nov 12, 2019 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShel... |
| CVE-2019-12719 | CRITICAL | 9.8 | 2.1% | Nov 12, 2019 | An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an inc... |
| CVE-2019-0721 | CRITICAL | 9.1 | 10.3% | Nov 12, 2019 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali... |
| CVE-2019-0719 | CRITICAL | 9.1 | 10.7% | Nov 12, 2019 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali... |
| CVE-2019-18925 | CRITICAL | 9.8 | 1.4% | Nov 12, 2019 | Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. |
| CVE-2019-18655 | CRITICAL | 9.8 | 14.7% | Nov 12, 2019 | File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera... |
| CVE-2019-18658 | CRITICAL | 9.8 | 1.7% | Nov 12, 2019 | In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport... |
| CVE-2019-18873 | CRITICAL | 9 | 8.2% | Nov 12, 2019 | FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An ... |
| CVE-2019-18852 | CRITICAL | 9.8 | 1.5% | Nov 11, 2019 | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign ... |
| CVE-2019-18623 | CRITICAL | 9.8 | 1.5% | Nov 8, 2019 | Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clic... |
| CVE-2019-18835 | CRITICAL | 9.8 | 0.9% | Nov 8, 2019 | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_le... |
| CVE-2019-18818 | CRITICAL | 9.8 | 97.6% | Nov 7, 2019 | strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s... |
| CVE-2019-11996 | CRITICAL | 9.8 | 1.5% | Nov 7, 2019 | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurati... |
| CVE-2019-18814 | CRITICAL | 9.8 | 2.5% | Nov 7, 2019 | An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_a... |
| CVE-2019-16872 | CRITICAL | 9.9 | 1.4% | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 1 of 4). |
| CVE-2019-18805 | CRITICAL | 9.8 | 3.4% | Nov 7, 2019 | An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c... |
| CVE-2019-12419 | CRITICAL | 9.8 | 13.8% | Nov 6, 2019 | Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Conn... |
| CVE-2019-5644 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a... |
| CVE-2019-5617 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now