2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5315 | HIGH | 7.2 | 2.2% | Sep 13, 2019 | A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated us... |
| CVE-2019-5314 | MEDIUM | 6.1 | 0.6% | Sep 13, 2019 | Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS... |
| CVE-2019-16293 | HIGH | 8.8 | 1.6% | Sep 13, 2019 | The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS comma... |
| CVE-2019-13923 | CRITICAL | 9.6 | 1.1% | Sep 13, 2019 | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration ... |
| CVE-2019-13922 | LOW | 2.7 | 0.6% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). An attacker with administ... |
| CVE-2019-13920 | MEDIUM | 4.3 | 0.4% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some parts of the web app... |
| CVE-2019-13919 | MEDIUM | 4.3 | 0.8% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). Some pages that should on... |
| CVE-2019-13918 | CRITICAL | 9.8 | 1.5% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no ... |
| CVE-2019-13548 | CRITICAL | 9.8 | 5.9% | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque... |
| CVE-2019-13532 | HIGH | 7.5 | 3.2% | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque... |
| CVE-2019-10937 | HIGH | 7.5 | 1.5% | Sep 13, 2019 | A vulnerability has been identified in SIMATIC TDC CP51M1 (All versions < V1.1.7). An attacker with network access to th... |
| CVE-2019-16289 | MEDIUM | 5.4 | 1.0% | Sep 13, 2019 | The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item para... |
| CVE-2019-16288 | HIGH | 7.5 | 1.4% | Sep 13, 2019 | On Tenda N301 wireless routers, a long string in the wifiSSID parameter of a goform/setWifi POST request causes the devi... |
| CVE-2019-3646 | MEDIUM | 6.5 | 1.5% | Sep 13, 2019 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Tri... |
| CVE-2019-15031 | MEDIUM | 4.4 | 0.6% | Sep 13, 2019 | In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce... |
| CVE-2019-15030 | MEDIUM | 4.4 | 0.5% | Sep 13, 2019 | In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' proce... |
| CVE-2019-13364 | CRITICAL | 9.6 | 1.4% | Sep 13, 2019 | admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_... |
| CVE-2019-13363 | CRITICAL | 9.6 | 1.4% | Sep 13, 2019 | admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mai... |
| CVE-2019-12922 | MEDIUM | 6.5 | 10.2% | Sep 13, 2019 | A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page. |
| CVE-2019-12517 | MEDIUM | 6.1 | 1.2% | Sep 13, 2019 | An XSS issue was discovered in the slickquiz plugin through 1.3.7.1 for WordPress. The save_quiz_score functionality ava... |
| CVE-2019-12516 | HIGH | 8.8 | 2.3% | Sep 13, 2019 | The slickquiz plugin through 1.3.7.1 for WordPress allows SQL Injection by Subscriber users, as demonstrated by a /wp-ad... |
| CVE-2019-16277 | HIGH | 7.8 | 0.9% | Sep 13, 2019 | PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionC... |
| CVE-2019-16275 | MEDIUM | 6.5 | 1.2% | Sep 12, 2019 | hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations ... |
| CVE-2019-13534 | HIGH | 7.2 | 0.7% | Sep 12, 2019 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ... |
| CVE-2019-13530 | HIGH | 7.2 | 1.4% | Sep 12, 2019 | Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN Version A, Firmware A.03.09, ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now