2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13556 | HIGH | 8.8 | 2.1% | Sep 18, 2019 | In WebAccess versions 8.4.1 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack of prop... |
| CVE-2019-11664 | MEDIUM | 6.5 | 0.5% | Sep 18, 2019 | Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40,... |
| CVE-2019-11663 | MEDIUM | 6.5 | 0.5% | Sep 18, 2019 | Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9... |
| CVE-2019-11662 | MEDIUM | 4.3 | 0.7% | Sep 18, 2019 | Class and method names in error message in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.... |
| CVE-2019-11661 | HIGH | 8.3 | 1.0% | Sep 18, 2019 | Allow changes to some table by non-SysAdmin in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34... |
| CVE-2019-5534 | HIGH | 7.7 | 1.6% | Sep 18, 2019 | VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc... |
| CVE-2019-5532 | HIGH | 7.7 | 1.9% | Sep 18, 2019 | VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc... |
| CVE-2019-5067 | CRITICAL | 9.8 | 3.4% | Sep 18, 2019 | An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object poi... |
| CVE-2019-5066 | CRITICAL | 9.8 | 2.4% | Sep 18, 2019 | An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 fo... |
| CVE-2019-5042 | HIGH | 8.8 | 2.1% | Sep 18, 2019 | An exploitable Use-After-Free vulnerability exists in the way FunctionType 0 PDF elements are processed in Aspose.PDF 19... |
| CVE-2019-15301 | CRITICAL | 9.8 | 1.5% | Sep 18, 2019 | A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13... |
| CVE-2019-13552 | HIGH | 8.8 | 2.7% | Sep 18, 2019 | In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validat... |
| CVE-2019-13550 | CRITICAL | 9.8 | 2.8% | Sep 18, 2019 | In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensit... |
| CVE-2019-9680 | MEDIUM | 5.3 | 1.4% | Sep 18, 2019 | Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of... |
| CVE-2019-9679 | HIGH | 8.8 | 0.9% | Sep 18, 2019 | Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after... |
| CVE-2019-9678 | HIGH | 7.5 | 1.0% | Sep 18, 2019 | Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crash... |
| CVE-2019-9677 | CRITICAL | 9.8 | 1.1% | Sep 18, 2019 | The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer ov... |
| CVE-2019-14458 | HIGH | 7.5 | 1.9% | Sep 18, 2019 | VIVOTEK IP Camera devices with firmware before 0x20x allow a denial of service via a crafted HTTP header. |
| CVE-2019-1975 | MEDIUM | 6.1 | 1.2% | Sep 18, 2019 | A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker t... |
| CVE-2019-12620 | MEDIUM | 5.3 | 0.7% | Sep 18, 2019 | A vulnerability in the statistics collection service of Cisco HyperFlex Software could allow an unauthenticated, remote ... |
| CVE-2019-14254 | CRITICAL | 9.8 | 1.5% | Sep 18, 2019 | An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are m... |
| CVE-2019-14253 | MEDIUM | 6.5 | 1.1% | Sep 18, 2019 | An issue was discovered in servletcontroller in the secure portal in Publisure 2.1.2. One can bypass authentication and ... |
| CVE-2019-14252 | HIGH | 7.2 | 1.5% | Sep 18, 2019 | An issue was discovered in the secure portal in Publisure 2.1.2. Once successfully authenticated as an administrator, on... |
| CVE-2019-15843 | HIGH | 7.4 | 0.8% | Sep 18, 2019 | A malicious file upload vulnerability was discovered in Xiaomi Millet mobile phones 1-6.3.9.3. A particular condition in... |
| CVE-2019-16399 | CRITICAL | 9.8 | 7.1% | Sep 18, 2019 | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now