2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-17082CRITICAL9Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on ...
CVE-2019-20461CRITICAL9.8An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control...
CVE-2019-20457CRITICAL9.1An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retr...
CVE-2019-25217CRITICAL9.8The SiteGround Optimizer plugin for WordPress is vulnerable to authorization bypass leading to Remote Code Execution and...
CVE-2019-25154CRITICAL9.6Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially p...
CVE-2019-16639CRITICAL9.8An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, whi...
CVE-2019-25211CRITICAL9.1parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g.,...
CVE-2019-19755CRITICAL9.1ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks a...
CVE-2019-19753CRITICAL9.1SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle ...
CVE-2019-19752CRITICAL9.8nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and ...
CVE-2019-25159CRITICAL9.8A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This...
CVE-2019-25158CRITICAL9.8A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects th...
CVE-2019-19450CRITICAL9.8paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untr...
CVE-2019-13690CRITICAL9.6Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a remote attacker to perfo...
CVE-2019-25136CRITICAL10A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code exec...
CVE-2019-25141CRITICAL9.8The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.3.9. Thi...
CVE-2019-25138CRITICAL9.8The User Submitted Posts plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2019-19791CRITICAL9.8In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restric...
CVE-2019-25101CRITICAL9.8A vulnerability classified as critical has been found in OnShift TurboGears 1.0.11.10. This affects an unknown part of t...
CVE-2019-25100CRITICAL9.8A vulnerability was found in happyman twmap. It has been declared as critical. Affected by this vulnerability is an unkn...
CVE-2019-25098CRITICAL9.8A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknow...
CVE-2019-25097CRITICAL9.8A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some ...
CVE-2019-11851CRITICAL9.8The ACENet service in Sierra Wireless ALEOS before 4.4.9, 4.5.x through 4.9.x before 4.9.5, and 4.10.x through 4.13.x be...
CVE-2019-15167CRITICAL9.1The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a differ...
CVE-2019-4575CRITICAL9.8IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.2.0 through 3.2.9 is vulnerable to SQL injec...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now