2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17512 | CRITICAL | 9.1 | 1.5% | Oct 16, 2019 | There are some web interfaces without authentication requirements on D-Link DIR-412 A1-1.14WW routers. An attacker can c... |
| CVE-2019-16700 | CRITICAL | 9.8 | 2.5% | Oct 16, 2019 | The slub_events (aka SLUB: Event Registration) extension through 3.0.2 for TYPO3 allows uploading of arbitrary files to ... |
| CVE-2019-16699 | CRITICAL | 9.8 | 2.4% | Oct 16, 2019 | The sr_freecap (aka freeCap CAPTCHA) extension 2.4.5 and below and 2.5.2 and below for TYPO3 fails to sanitize user inpu... |
| CVE-2019-15260 | CRITICAL | 9.8 | 3.0% | Oct 16, 2019 | A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain un... |
| CVE-2019-3025 | CRITICAL | 9 | 14.5% | Oct 16, 2019 | Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi... |
| CVE-2019-3020 | CRITICAL | 9.3 | 1.5% | Oct 16, 2019 | Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering... |
| CVE-2019-2904 | CRITICAL | 9.8 | 14.3% | Oct 16, 2019 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported ver... |
| CVE-2019-17662 | CRITICAL | 9.8 | 96.8% | Oct 16, 2019 | ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi... |
| CVE-2019-6334 | CRITICAL | 9.8 | 3.6% | Oct 16, 2019 | HP LaserJet, PageWide, OfficeJet Enterprise, and LaserJet Managed Printers have a solution to check application signatur... |
| CVE-2019-10458 | CRITICAL | 9.9 | 1.9% | Oct 16, 2019 | Jenkins Puppet Enterprise Pipeline 1.3.1 and earlier specifies unsafe values in its custom Script Security whitelist, al... |
| CVE-2019-17626 | CRITICAL | 9.8 | 10.2% | Oct 16, 2019 | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a c... |
| CVE-2019-17625 | CRITICAL | 9 | 3.0% | Oct 16, 2019 | There is a stored XSS in Rambox 0.6.9 that can lead to code execution. The XSS is in the name field while adding/editing... |
| CVE-2019-17613 | CRITICAL | 9.8 | 2.9% | Oct 15, 2019 | qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction ... |
| CVE-2019-17395 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication,... |
| CVE-2019-17602 | CRITICAL | 9.8 | 81.5% | Oct 15, 2019 | An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is ... |
| CVE-2019-17601 | CRITICAL | 9.8 | 2.8% | Oct 15, 2019 | In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achi... |
| CVE-2019-17398 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Dark Horse Comics application 1.3.21 for Android, token information (equivalent to the username and password) is ... |
| CVE-2019-17396 | CRITICAL | 9.8 | 1.2% | Oct 15, 2019 | In the PowerSchool Mobile application 1.1.8 for Android, the username and password are stored in the log during authenti... |
| CVE-2019-17394 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during au... |
| CVE-2019-17355 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the Orbitz application 19.31.1 for Android, the username and password are stored in the log during authentication, an... |
| CVE-2019-17397 | CRITICAL | 9.8 | 1.3% | Oct 15, 2019 | In the DoorDash application through 11.5.2 for Android, the username and password are stored in the log during authentic... |
| CVE-2019-10760 | CRITICAL | 9.9 | 2.9% | Oct 15, 2019 | safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape th... |
| CVE-2019-10759 | CRITICAL | 9.9 | 1.8% | Oct 15, 2019 | safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape th... |
| CVE-2019-17600 | CRITICAL | 9.8 | 1.2% | Oct 15, 2019 | Intelbras IWR 1000N 1.6.4 devices allow disclosure of the administrator login name and password because v1/system/user i... |
| CVE-2019-17195 | CRITICAL | 9.8 | 11.0% | Oct 15, 2019 | Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now