2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20490 | HIGH | 8.8 | 1.1% | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499). |
| CVE-2019-11074 | HIGH | 7.2 | 4.5% | Mar 17, 2020 | A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attacke... |
| CVE-2019-20453 | HIGH | 8.8 | 2.1% | Mar 17, 2020 | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t... |
| CVE-2019-20452 | HIGH | 8.8 | 2.1% | Mar 17, 2020 | A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t... |
| CVE-2019-20326 | HIGH | 7.8 | 2.1% | Mar 16, 2020 | A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.... |
| CVE-2019-20191 | HIGH | 7.5 | 1.1% | Mar 16, 2020 | Oxygen XML Editor 21.1.1 allows XXE to read any file. |
| CVE-2019-19538 | HIGH | 7.2 | 3.1% | Mar 16, 2020 | In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command... |
| CVE-2019-19937 | HIGH | 7.2 | 1.5% | Mar 16, 2020 | In JFrog Artifactory before 6.18, it is not possible to restrict either system or repository imports by any admin user i... |
| CVE-2019-11073 | HIGH | 7.2 | 6.3% | Mar 16, 2020 | A Remote Code Execution vulnerability exists in PRTG Network Monitor before 19.4.54.1506 that allows attackers to execut... |
| CVE-2019-5543 | HIGH | 7.8 | 0.4% | Mar 16, 2020 | For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.... |
| CVE-2019-19945 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bou... |
| CVE-2019-19821 | HIGH | 8.1 | 1.4% | Mar 16, 2020 | A post-authentication privilege escalation in the web application of Combodo iTop allows regular authenticated users to ... |
| CVE-2019-19942 | HIGH | 7.5 | 1.6% | Mar 16, 2020 | Missing output sanitation in Swisscom Centro Grande Centro Grande before 6.16.12, Centro Business 1.0 (ADB) before 7.10.... |
| CVE-2019-19940 | HIGH | 7.2 | 4.9% | Mar 16, 2020 | Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allow... |
| CVE-2019-19135 | HIGH | 7.4 | 1.0% | Mar 16, 2020 | In OPC Foundation OPC UA .NET Standard codebase 1.4.357.28, servers do not create sufficiently random numbers in OPCFoun... |
| CVE-2019-19209 | HIGH | 7.5 | 2.1% | Mar 16, 2020 | Dolibarr ERP/CRM before 10.0.3 allows SQL Injection. |
| CVE-2019-10091 | HIGH | 7.4 | 1.4% | Mar 16, 2020 | When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verific... |
| CVE-2019-17654 | HIGH | 8.8 | 0.5% | Mar 15, 2020 | An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow ... |
| CVE-2019-9474 | HIGH | 7.5 | 0.8% | Mar 15, 2020 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio... |
| CVE-2019-9473 | HIGH | 7.5 | 0.8% | Mar 15, 2020 | In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio... |
| CVE-2019-2216 | HIGH | 7.3 | 0.2% | Mar 15, 2020 | In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a... |
| CVE-2019-2089 | HIGH | 7.8 | 0.2% | Mar 15, 2020 | In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could l... |
| CVE-2019-19611 | HIGH | 7.5 | 1.1% | Mar 13, 2020 | An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to a... |
| CVE-2019-14309 | HIGH | 7.5 | 1.2% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer... |
| CVE-2019-14303 | HIGH | 7.5 | 1.3% | Mar 13, 2020 | Ricoh SP C250DN 1.05 devices allow denial of service (issue 1 of 3). Some Ricoh printers were affected by a wrong LPD se... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now