2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17429 | CRITICAL | 9.8 | 1.4% | Oct 10, 2019 | Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter. |
| CVE-2019-17072 | CRITICAL | 9.8 | 1.9% | Oct 10, 2019 | The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Inj... |
| CVE-2019-17426 | CRITICAL | 9.1 | 1.7% | Oct 10, 2019 | Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query obj... |
| CVE-2019-17415 | CRITICAL | 9.8 | 4.4% | Oct 9, 2019 | A Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthen... |
| CVE-2019-1584 | CRITICAL | 9.8 | 2.8% | Oct 9, 2019 | A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if... |
| CVE-2019-15020 | CRITICAL | 9.8 | 0.9% | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.293 and earlier, that could allow an attacker to sup... |
| CVE-2019-15019 | CRITICAL | 9.8 | 1.5% | Oct 9, 2019 | A security vulnerability exists in the Zingbox Inspector versions 1.294 and earlier, that could allow an attacker to sup... |
| CVE-2019-9535 | CRITICAL | 9.8 | 2.5% | Oct 9, 2019 | A vulnerability exists in the way that iTerm2 integrates with tmux's control mode, which may allow an attacker to execut... |
| CVE-2019-17399 | CRITICAL | 9.8 | 1.7% | Oct 9, 2019 | The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment. |
| CVE-2019-17383 | CRITICAL | 9.8 | 2.3% | Oct 9, 2019 | The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 per... |
| CVE-2019-17124 | CRITICAL | 9.8 | 23.1% | Oct 9, 2019 | Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. |
| CVE-2019-15859 | CRITICAL | 9.8 | 34.1% | Oct 9, 2019 | Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get f... |
| CVE-2019-17382 | CRITICAL | 9.1 | 54.1% | Oct 9, 2019 | An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass ... |
| CVE-2019-17373 | CRITICAL | 9.8 | 1.5% | Oct 9, 2019 | Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, s... |
| CVE-2019-17354 | CRITICAL | 9.4 | 1.4% | Oct 9, 2019 | wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication,... |
| CVE-2019-17362 | CRITICAL | 9.1 | 3.2% | Oct 9, 2019 | In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detec... |
| CVE-2019-3980 | CRITICAL | 9.8 | 5.2% | Oct 8, 2019 | The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to... |
| CVE-2019-10757 | CRITICAL | 9.8 | 1.2% | Oct 8, 2019 | knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of th... |
| CVE-2019-17134 | CRITICAL | 9.1 | 2.3% | Oct 8, 2019 | Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the man... |
| CVE-2019-13336 | CRITICAL | 9.8 | 2.9% | Oct 8, 2019 | The dbell Wi-Fi Smart Video Doorbell DB01-S Gen 1 allows remote attackers to launch commands with no authentication veri... |
| CVE-2019-17042 | CRITICAL | 9.8 | 3.1% | Oct 7, 2019 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for ... |
| CVE-2019-17041 | CRITICAL | 9.8 | 4.6% | Oct 7, 2019 | An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the... |
| CVE-2019-12812 | CRITICAL | 9.8 | 2.7% | Oct 7, 2019 | MyBuilder viewer before 6.2.2019.814 allow an attacker to execute arbitrary command via specifically crafted configurati... |
| CVE-2019-12811 | CRITICAL | 9.8 | 2.2% | Oct 7, 2019 | ActiveX Control in MyBuilder before 6.2.2019.814 allow an attacker to execute arbitrary command via the ShellOpen method... |
| CVE-2019-15751 | CRITICAL | 9.8 | 4.5% | Oct 7, 2019 | An unrestricted file upload vulnerability in SITOS six Build v6.2.1 allows remote attackers to execute arbitrary code by... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now