2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15678 | CRITICAL | 9.8 | 13.1% | Oct 29, 2019 | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result cod... |
| CVE-2019-10749 | CRITICAL | 9.8 | 1.2% | Oct 29, 2019 | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly... |
| CVE-2019-10748 | CRITICAL | 9.8 | 1.3% | Oct 29, 2019 | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not bei... |
| CVE-2019-10211 | CRITICAL | 9.8 | 1.9% | Oct 29, 2019 | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu... |
| CVE-2019-18189 | CRITICAL | 9.8 | 4.5% | Oct 28, 2019 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5... |
| CVE-2019-17181 | CRITICAL | 9.8 | 48.7% | Oct 28, 2019 | A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET o... |
| CVE-2019-14450 | CRITICAL | 9.8 | 10.4% | Oct 28, 2019 | A directory traversal vulnerability was discovered in RepetierServer.exe in Repetier-Server 0.8 through 0.91 that allows... |
| CVE-2019-16897 | CRITICAL | 9.8 | 1.6% | Oct 28, 2019 | In K7 Antivirus Premium 16.0.xxx through 16.0.0120; K7 Total Security 16.0.xxx through 16.0.0120; and K7 Ultimate Securi... |
| CVE-2019-11043 | CRITICAL | 9.8 | 99.5% | Oct 28, 2019 | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it ... |
| CVE-2019-14931 | CRITICAL | 9.8 | 57.7% | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3... |
| CVE-2019-14930 | CRITICAL | 9.8 | 2.3% | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3... |
| CVE-2019-14929 | CRITICAL | 9.8 | 1.9% | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3... |
| CVE-2019-14926 | CRITICAL | 9.8 | 2.1% | Oct 28, 2019 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3... |
| CVE-2019-16662 | CRITICAL | 9.8 | 97.7% | Oct 28, 2019 | An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a... |
| CVE-2019-5129 | CRITICAL | 9.8 | 33.2% | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the... |
| CVE-2019-5128 | CRITICAL | 9.8 | 25.7% | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the... |
| CVE-2019-5127 | CRITICAL | 9.8 | 45.3% | Oct 25, 2019 | A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the... |
| CVE-2019-5114 | CRITICAL | 9.9 | 1.4% | Oct 25, 2019 | An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web ... |
| CVE-2019-13553 | CRITICAL | 9.8 | 1.8% | Oct 25, 2019 | Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mech... |
| CVE-2019-16265 | CRITICAL | 9.8 | 1.6% | Oct 25, 2019 | CODESYS V2.3 ENI server up to V3.2.2.24 has a Buffer Overflow. |
| CVE-2019-14451 | CRITICAL | 9.8 | 4.5% | Oct 25, 2019 | RepetierServer.exe in Repetier-Server 0.8 through 0.91 does not properly validate the XML data structure provided when u... |
| CVE-2019-8088 | CRITICAL | 9.8 | 5.8% | Oct 25, 2019 | Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation ... |
| CVE-2019-18418 | CRITICAL | 9.8 | 4.0% | Oct 24, 2019 | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be... |
| CVE-2019-18413 | CRITICAL | 9.8 | 2.0% | Oct 24, 2019 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can... |
| CVE-2019-15929 | CRITICAL | 9.8 | 1.6% | Oct 24, 2019 | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, lea... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now