2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5521 | CRITICAL | 9.6 | 1.6% | Sep 20, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-4565 | HIGH | 7.5 | 1.5% | Sep 20, 2019 | IBM Security Key Lifecycle Manager 3.0 and 3.0.1 does not require that users should have strong passwords by default, wh... |
| CVE-2019-4505 | MEDIUM | 5.3 | 2.4% | Sep 20, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensi... |
| CVE-2019-16644 | CRITICAL | 9.8 | 1.4% | Sep 20, 2019 | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= s... |
| CVE-2019-16643 | MEDIUM | 5.4 | 0.6% | Sep 20, 2019 | An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area. |
| CVE-2019-16534 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE:... |
| CVE-2019-16533 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to ... |
| CVE-2019-16642 | CRITICAL | 9.8 | 1.5% | Sep 20, 2019 | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/gr... |
| CVE-2019-15089 | HIGH | 8.8 | 0.6% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Forms have no CSRF protection, letting an attacker execute actions as the a... |
| CVE-2019-15088 | CRITICAL | 9.8 | 1.7% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under speci... |
| CVE-2019-15087 | HIGH | 7.2 | 3.3% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any... |
| CVE-2019-15086 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The newentityID parameter is not properly escaped, leading to a reflected X... |
| CVE-2019-15085 | HIGH | 7.5 | 1.4% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The current database password is embedded in the change password form. |
| CVE-2019-14916 | MEDIUM | 6.5 | 1.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. A file's format is not properly checked, leading to an unrestricted file up... |
| CVE-2019-14915 | MEDIUM | 6.1 | 0.5% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Certificate data are not properly escaped. This leads to XSS when submittin... |
| CVE-2019-14914 | CRITICAL | 9.1 | 2.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to a... |
| CVE-2019-14913 | MEDIUM | 5.4 | 0.9% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Log data are not properly escaped, leading to persistent XSS in the adminis... |
| CVE-2019-14912 | MEDIUM | 6.1 | 1.2% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to a... |
| CVE-2019-14911 | MEDIUM | 6.1 | 1.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly escape output on error, leading to ref... |
| CVE-2019-16531 | HIGH | 8.8 | 2.5% | Sep 20, 2019 | LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php. |
| CVE-2019-9720 | MEDIUM | 6.5 | 1.1% | Sep 19, 2019 | A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ... |
| CVE-2019-9719 | HIGH | 8.8 | 2.0% | Sep 19, 2019 | A stack-based buffer overflow in the subtitle decoder in Libav 12.3 allows attackers to corrupt the stack via a crafted ... |
| CVE-2019-9717 | MEDIUM | 6.5 | 1.3% | Sep 19, 2019 | In Libav 12.3, a denial of service in the subtitle decoder allows attackers to hog the CPU via a crafted video file in M... |
| CVE-2019-9619 | — | — | — | Sep 19, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-16525 | MEDIUM | 6.1 | 5.5% | Sep 19, 2019 | An XSS issue was discovered in the checklist plugin before 1.1.9 for WordPress. The fill parameter is not correctly filt... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now