2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16066 | HIGH | 8.8 | 2.2% | Mar 19, 2020 | An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 an... |
| CVE-2019-16065 | HIGH | 8.8 | 2.8% | Mar 19, 2020 | A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a... |
| CVE-2019-16061 | HIGH | 8.8 | 1.0% | Mar 19, 2020 | A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable pe... |
| CVE-2019-15656 | HIGH | 7.5 | 1.3% | Mar 19, 2020 | D-Link DSL-2875AL and DSL-2877AL devices through 1.00.05 are prone to information disclosure via a simple crafted reques... |
| CVE-2019-15655 | HIGH | 7.5 | 1.4% | Mar 19, 2020 | D-Link DSL-2875AL devices through 1.00.05 are prone to password disclosure via a simple crafted /romfile.cfg request to ... |
| CVE-2019-15654 | HIGH | 7.5 | 1.5% | Mar 19, 2020 | Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download... |
| CVE-2019-15653 | HIGH | 7.5 | 0.8% | Mar 19, 2020 | Comba AP2600-I devices through A02,0202N00PD2 are prone to password disclosure via an insecure authentication mechanism.... |
| CVE-2019-11361 | HIGH | 8.8 | 3.0% | Mar 19, 2020 | Zoho ManageEngine Remote Access Plus 10.0.258 does not validate user permissions properly, allowing for privilege escala... |
| CVE-2019-16012 | HIGH | 8.1 | 54.2% | Mar 19, 2020 | A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to... |
| CVE-2019-18979 | HIGH | 7.8 | 0.4% | Mar 18, 2020 | Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation u... |
| CVE-2019-3762 | HIGH | 7.5 | 0.6% | Mar 18, 2020 | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulner... |
| CVE-2019-20529 | HIGH | 7.5 | 1.3% | Mar 18, 2020 | In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were b... |
| CVE-2019-18582 | HIGH | 7.2 | 4.6% | Mar 18, 2020 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat... |
| CVE-2019-18581 | HIGH | 7.2 | 3.9% | Mar 18, 2020 | Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to pat... |
| CVE-2019-12769 | HIGH | 8.8 | 0.8% | Mar 18, 2020 | SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forg... |
| CVE-2019-12123 | HIGH | 8.8 | 1.3% | Mar 18, 2020 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsXml with a crafted module parameter, an auth... |
| CVE-2019-12121 | HIGH | 7.5 | 0.7% | Mar 18, 2020 | An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSi... |
| CVE-2019-12113 | HIGH | 8.8 | 1.3% | Mar 18, 2020 | An issue was discovered in ONAP SDNC before Dublin. By executing sla/printAsGv with a crafted module parameter, an authe... |
| CVE-2019-19355 | HIGH | 7 | 0.2% | Mar 18, 2020 | An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An a... |
| CVE-2019-19351 | HIGH | 7 | 0.2% | Mar 18, 2020 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker... |
| CVE-2019-11689 | HIGH | 8.1 | 3.2% | Mar 18, 2020 | An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf... |
| CVE-2019-11688 | HIGH | 7.4 | 1.1% | Mar 18, 2020 | An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf... |
| CVE-2019-10682 | HIGH | 7.5 | 1.0% | Mar 18, 2020 | django-nopassword before 5.0.0 stores cleartext secrets in the database. |
| CVE-2019-11939 | HIGH | 7.5 | 1.5% | Mar 18, 2020 | Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the pay... |
| CVE-2019-20492 | HIGH | 8.8 | 1.3% | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516). |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now