2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17026 | HIGH | 8.8 | 46.6% | Mar 2, 2020 | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are ... |
| CVE-2019-7007 | HIGH | 8.6 | 1.7% | Feb 28, 2020 | A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. ... |
| CVE-2019-4301 | HIGH | 8.4 | 1.2% | Feb 28, 2020 | BigFix Self-Service Application (SSA) is vulnerable to arbitrary code execution if Javascript code is included in Runnin... |
| CVE-2019-10805 | HIGH | 7.5 | 1.4% | Feb 28, 2020 | valib through 2.0.0 allows Internal Property Tampering. A maliciously crafted JavaScript object can bypass several inspe... |
| CVE-2019-19943 | HIGH | 7.5 | 4.3% | Feb 28, 2020 | The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corru... |
| CVE-2019-10064 | HIGH | 7.5 | 3.7% | Feb 28, 2020 | hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding... |
| CVE-2019-8741 | HIGH | 7.5 | 2.4% | Feb 28, 2020 | A denial of service issue was addressed with improved input validation. |
| CVE-2019-3698 | HIGH | 7 | 0.7% | Feb 28, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server ... |
| CVE-2019-5326 | HIGH | 7.2 | 1.9% | Feb 27, 2020 | An administrative application user of or application user with write access to Aruba Airwave VisualRF is able to obtain ... |
| CVE-2019-5323 | HIGH | 7.2 | 2.6% | Feb 27, 2020 | There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an ad... |
| CVE-2019-18238 | HIGH | 7.5 | 0.5% | Feb 26, 2020 | In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, ... |
| CVE-2019-17274 | HIGH | 7.8 | 0.6% | Feb 26, 2020 | NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were ship... |
| CVE-2019-19989 | HIGH | 7.5 | 1.3% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of... |
| CVE-2019-19988 | HIGH | 8.8 | 1.5% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. A user with valid credentials is abl... |
| CVE-2019-19986 | HIGH | 7.5 | 1.3% | Feb 26, 2020 | An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. An attacker without authentication i... |
| CVE-2019-4000 | HIGH | 7.8 | 0.7% | Feb 25, 2020 | Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, ... |
| CVE-2019-3999 | HIGH | 7.8 | 8.6% | Feb 25, 2020 | Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u... |
| CVE-2019-5165 | HIGH | 7.2 | 2.2% | Feb 25, 2020 | An exploitable authentication bypass vulnerability exists in the hostname processing of the Moxa AWK-3131A firmware vers... |
| CVE-2019-5162 | HIGH | 8.8 | 2.7% | Feb 25, 2020 | An exploitable improper access control vulnerability exists in the iw_webs account settings functionality of the Moxa AW... |
| CVE-2019-5153 | HIGH | 8.8 | 4.6% | Feb 25, 2020 | An exploitable remote code execution vulnerability exists in the iw_webs configuration parsing functionality of the Moxa... |
| CVE-2019-5148 | HIGH | 7.5 | 2.5% | Feb 25, 2020 | An exploitable denial-of-service vulnerability exists in ServiceAgent functionality of the Moxa AWK-3131A, firmware vers... |
| CVE-2019-5143 | HIGH | 8.8 | 4.7% | Feb 25, 2020 | An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A f... |
| CVE-2019-5142 | HIGH | 7.2 | 6.9% | Feb 25, 2020 | An exploitable command injection vulnerability exists in the hostname functionality of the Moxa AWK-3131A firmware versi... |
| CVE-2019-5141 | HIGH | 8.8 | 5.1% | Feb 25, 2020 | An exploitable command injection vulnerability exists in the iw_webs functionality of the Moxa AWK-3131A firmware versio... |
| CVE-2019-5140 | HIGH | 8.8 | 2.9% | Feb 25, 2020 | An exploitable command injection vulnerability exists in the iwwebs functionality of the Moxa AWK-3131A firmware version... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now