2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19034 | HIGH | 7.2 | 6.0% | Mar 23, 2020 | Zoho ManageEngine Asset Explorer 6.5 does not validate the System Center Configuration Manager (SCCM) database username ... |
| CVE-2019-5186 | HIGH | 7 | 0.8% | Mar 23, 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit... |
| CVE-2019-5185 | HIGH | 7 | 0.8% | Mar 23, 2020 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service "I/O-Check" functionalit... |
| CVE-2019-5184 | HIGH | 7.8 | 0.8% | Mar 23, 2020 | An exploitable double free vulnerability exists in the iocheckd service "I/O-Check" functionality of WAGO PFC 200. A spe... |
| CVE-2019-18936 | HIGH | 7.5 | 1.5% | Mar 21, 2020 | UniValue::read() in UniValue before 1.0.5 allow attackers to cause a denial of service (the class internal data reaches ... |
| CVE-2019-17185 | HIGH | 7.5 | 2.2% | Mar 21, 2020 | In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. Th... |
| CVE-2019-16528 | HIGH | 7.5 | 1.3% | Mar 20, 2020 | An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attacker... |
| CVE-2019-19324 | HIGH | 7.5 | 1.0% | Mar 20, 2020 | Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted a... |
| CVE-2019-15665 | HIGH | 7.2 | 2.6% | Mar 20, 2020 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida... |
| CVE-2019-15075 | HIGH | 7.5 | 0.4% | Mar 20, 2020 | An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have ... |
| CVE-2019-15661 | HIGH | 7.2 | 2.4% | Mar 20, 2020 | An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida... |
| CVE-2019-14855 | HIGH | 7.5 | 1.1% | Mar 20, 2020 | A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An att... |
| CVE-2019-19345 | HIGH | 7.8 | 0.3% | Mar 20, 2020 | A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification v... |
| CVE-2019-19487 | HIGH | 8.8 | 5.3% | Mar 20, 2020 | Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection ... |
| CVE-2019-19029 | HIGH | 7.2 | 2.1% | Mar 20, 2020 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Har... |
| CVE-2019-19025 | HIGH | 8.8 | 1.0% | Mar 20, 2020 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry fo... |
| CVE-2019-19023 | HIGH | 8.8 | 1.6% | Mar 20, 2020 | Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware... |
| CVE-2019-18785 | HIGH | 7.5 | 1.0% | Mar 20, 2020 | SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. |
| CVE-2019-16108 | HIGH | 7.5 | 1.1% | Mar 20, 2020 | phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode. |
| CVE-2019-16071 | HIGH | 8.8 | 1.0% | Mar 20, 2020 | Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability t... |
| CVE-2019-16068 | HIGH | 8.8 | 0.9% | Mar 19, 2020 | A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri... |
| CVE-2019-16063 | HIGH | 7.5 | 0.7% | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an atta... |
| CVE-2019-16338 | HIGH | 7.8 | 1.0% | Mar 19, 2020 | The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file. |
| CVE-2019-16337 | HIGH | 7.8 | 1.1% | Mar 19, 2020 | The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file. |
| CVE-2019-16067 | HIGH | 7.5 | 0.8% | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web appli... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now