2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14844 | HIGH | 7.5 | 4.4% | Sep 26, 2019 | A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash ... |
| CVE-2019-14273 | MEDIUM | 5.3 | 1.1% | Sep 26, 2019 | In SilverStripe assets 4.0, there is broken access control on files. |
| CVE-2019-14272 | MEDIUM | 5.4 | 0.7% | Sep 26, 2019 | In SilverStripe asset-admin 4.0, there is XSS in file titles managed through the CMS. |
| CVE-2019-12617 | LOW | 2.7 | 0.9% | Sep 26, 2019 | In SilverStripe through 4.3.3, there is access escalation for CMS users with limited access through permission cache pol... |
| CVE-2019-16903 | MEDIUM | 5.3 | 1.9% | Sep 26, 2019 | Platinum UPnP SDK 1.2.0 allows Directory Traversal in Core/PltHttpServer.cpp because it checks for /.. where it should b... |
| CVE-2019-16738 | MEDIUM | 5.3 | 1.8% | Sep 26, 2019 | In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup... |
| CVE-2019-16901 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x00000000... |
| CVE-2019-16900 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c. |
| CVE-2019-16899 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfo... |
| CVE-2019-16253 | HIGH | 7.8 | 1.2% | Sep 25, 2019 | The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacke... |
| CVE-2019-16892 | MEDIUM | 5.5 | 1.6% | Sep 25, 2019 | In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the unco... |
| CVE-2019-16890 | MEDIUM | 5.4 | 0.7% | Sep 25, 2019 | Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments. |
| CVE-2019-12717 | HIGH | 7.8 | 0.4% | Sep 25, 2019 | A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an aut... |
| CVE-2019-12709 | MEDIUM | 6.7 | 0.5% | Sep 25, 2019 | A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 900... |
| CVE-2019-12672 | MEDIUM | 6.8 | 0.6% | Sep 25, 2019 | A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker with physical ac... |
| CVE-2019-12671 | HIGH | 7.8 | 0.4% | Sep 25, 2019 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to gain shell access on... |
| CVE-2019-12670 | MEDIUM | 6.7 | 0.3% | Sep 25, 2019 | A vulnerability in the filesystem of Cisco IOS XE Software could allow an authenticated, local attacker within the IOx G... |
| CVE-2019-12669 | HIGH | 7.5 | 1.8% | Sep 25, 2019 | A vulnerability in the RADIUS Change of Authorization (CoA) code of Cisco TrustSec, a feature within Cisco IOS XE Softwa... |
| CVE-2019-12668 | MEDIUM | 4.8 | 0.8% | Sep 25, 2019 | A vulnerability in the web framework code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote at... |
| CVE-2019-12667 | MEDIUM | 4.8 | 0.8% | Sep 25, 2019 | A vulnerability in the web framework code of Cisco IOS XE Software could allow an authenticated, remote attacker to cond... |
| CVE-2019-12666 | MEDIUM | 6.7 | 1.1% | Sep 25, 2019 | A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform dire... |
| CVE-2019-12665 | HIGH | 7.4 | 1.1% | Sep 25, 2019 | A vulnerability in the HTTP client feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attac... |
| CVE-2019-12664 | HIGH | 7.5 | 1.4% | Sep 25, 2019 | A vulnerability in the Dialer interface feature for ISDN connections in Cisco IOS XE Software for Cisco 4000 Series Inte... |
| CVE-2019-12663 | HIGH | 8.6 | 1.8% | Sep 25, 2019 | A vulnerability in the Cisco TrustSec (CTS) Protected Access Credential (PAC) provisioning module of Cisco IOS XE Softwa... |
| CVE-2019-12662 | MEDIUM | 6.7 | 0.3% | Sep 25, 2019 | A vulnerability in Cisco NX-OS Software and Cisco IOS XE Software could allow an authenticated, local attacker with vali... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now