2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15748 | CRITICAL | 9.8 | 1.6% | Oct 7, 2019 | SITOS six Build v6.2.1 permits unauthorised users to upload and import a SCORM 2004 package by browsing directly to affe... |
| CVE-2019-15746 | CRITICAL | 9.8 | 1.9% | Oct 7, 2019 | SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the ... |
| CVE-2019-17269 | CRITICAL | 9.8 | 3.1% | Oct 7, 2019 | Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Pi... |
| CVE-2019-17267 | CRITICAL | 9.8 | 4.6% | Oct 7, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to net.sf.ehcache.h... |
| CVE-2019-17266 | CRITICAL | 9.8 | 2.8% | Oct 6, 2019 | libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup... |
| CVE-2019-17240 | CRITICAL | 9.8 | 39.6% | Oct 6, 2019 | bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many... |
| CVE-2019-17218 | CRITICAL | 9.1 | 0.7% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the commu... |
| CVE-2019-17216 | CRITICAL | 9.8 | 0.7% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. Password authenticati... |
| CVE-2019-17215 | CRITICAL | 9.8 | 1.2% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no bruteforc... |
| CVE-2019-17206 | CRITICAL | 9.8 | 3.2% | Oct 5, 2019 | Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.... |
| CVE-2019-17197 | CRITICAL | 9.8 | 1.5% | Oct 5, 2019 | OpenEMR through 5.0.2 has SQL Injection in the Lifestyle demographic filter criteria in library/clinical_rules.php that ... |
| CVE-2019-17192 | CRITICAL | 9.8 | 2.7% | Oct 5, 2019 | The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing ... |
| CVE-2019-17184 | CRITICAL | 9.8 | 1.5% | Oct 4, 2019 | Xerox AtlaLink B8045/B8055/B8065/B8075/B8090 C8030/C8035/C8045/C8055/C8070 printers with software before 101.00x.089.226... |
| CVE-2019-16891 | CRITICAL | 9.8 | 45.7% | Oct 4, 2019 | Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload. |
| CVE-2019-17133 | CRITICAL | 9.8 | 6.7% | Oct 4, 2019 | In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE,... |
| CVE-2019-17132 | CRITICAL | 9.8 | 11.8% | Oct 4, 2019 | vBulletin through 5.5.4 mishandles custom avatars. |
| CVE-2019-17113 | CRITICAL | 9.8 | 2.7% | Oct 4, 2019 | In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.... |
| CVE-2019-13957 | CRITICAL | 9.8 | 1.4% | Oct 2, 2019 | In Umbraco 7.3.8, there is SQL Injection in the backoffice/PageWApprove/PageWApproveApi/GetInpectSearch method via the n... |
| CVE-2019-12736 | CRITICAL | 9.8 | 2.2% | Oct 2, 2019 | JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, lead... |
| CVE-2019-12630 | CRITICAL | 9.8 | 65.8% | Oct 2, 2019 | A vulnerability in the Java deserialization function used by Cisco Security Manager could allow an unauthenticated, remo... |
| CVE-2019-12157 | CRITICAL | 9.8 | 1.8% | Oct 2, 2019 | In JetBrains UpSource versions before 2018.2 build 1293, there is credential disclosure via RPC commands. |
| CVE-2019-11929 | CRITICAL | 9.8 | 4.0% | Oct 2, 2019 | Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, ... |
| CVE-2019-10212 | CRITICAL | 9.8 | 1.9% | Oct 2, 2019 | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attack... |
| CVE-2019-13658 | CRITICAL | 9.8 | 3.4% | Oct 2, 2019 | CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to exec... |
| CVE-2019-13025 | CRITICAL | 9.8 | 3.3% | Oct 2, 2019 | Compal CH7465LG CH7465LG-NCIP-6.12.18.24-5p8-NOSH devices have Incorrect Access Control because of Improper Input Valida... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now