2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5094 | HIGH | 7.5 | 1.1% | Sep 24, 2019 | An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially craf... |
| CVE-2019-16759 | CRITICAL | 9.8 | 99.7% | Sep 24, 2019 | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge... |
| CVE-2019-13528 | MEDIUM | 4.4 | 0.4% | Sep 24, 2019 | A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE ... |
| CVE-2019-13527 | HIGH | 7.8 | 5.3% | Sep 24, 2019 | In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Aren... |
| CVE-2019-16725 | MEDIUM | 6.1 | 0.7% | Sep 24, 2019 | In Joomla! 3.x before 3.9.12, inadequate escaping allowed XSS attacks using the logo parameter of the default templates. |
| CVE-2019-16724 | CRITICAL | 9.8 | 72.2% | Sep 24, 2019 | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti... |
| CVE-2019-14220 | MEDIUM | 6.5 | 0.9% | Sep 24, 2019 | An issue was discovered in BlueStacks 4.110 and below on macOS and on 4.120 and below on Windows. BlueStacks employs And... |
| CVE-2019-5505 | CRITICAL | 9.8 | 0.8% | Sep 24, 2019 | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. |
| CVE-2019-5504 | CRITICAL | 9.8 | 2.0% | Sep 24, 2019 | ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowin... |
| CVE-2019-16411 | CRITICAL | 9.8 | 2.0% | Sep 24, 2019 | An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function ... |
| CVE-2019-16410 | CRITICAL | 9.1 | 2.1% | Sep 24, 2019 | An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble i... |
| CVE-2019-15699 | CRITICAL | 9.1 | 1.6% | Sep 24, 2019 | An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the par... |
| CVE-2019-12068 | LOW | 3.8 | 0.5% | Sep 24, 2019 | In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-1... |
| CVE-2019-14239 | MEDIUM | 6.6 | 0.4% | Sep 24, 2019 | On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method... |
| CVE-2019-16754 | HIGH | 7.5 | 1.5% | Sep 24, 2019 | RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attac... |
| CVE-2019-16751 | MEDIUM | 6.1 | 0.9% | Sep 24, 2019 | An issue was discovered in Devise Token Auth through 1.1.2. The omniauth failure endpoint is vulnerable to Reflected Cro... |
| CVE-2019-14238 | MEDIUM | 6.6 | 0.4% | Sep 24, 2019 | On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) ca... |
| CVE-2019-14753 | HIGH | 7.5 | 1.2% | Sep 24, 2019 | SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow |
| CVE-2019-3726 | MEDIUM | 6.7 | 0.5% | Sep 24, 2019 | An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versi... |
| CVE-2019-16383 | CRITICAL | 9.4 | 5.2% | Sep 24, 2019 | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a... |
| CVE-2019-13357 | HIGH | 7.8 | 0.6% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allo... |
| CVE-2019-13356 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-13355 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-4566 | MEDIUM | 5.5 | 0.2% | Sep 24, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a l... |
| CVE-2019-4515 | MEDIUM | 6.5 | 0.5% | Sep 24, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 is vulnerable to cross-site request forgery which could allow an attack... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now