2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11734 | CRITICAL | 9.8 | 1.3% | Sep 27, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed ev... |
| CVE-2019-11733 | CRITICAL | 9.8 | 1.4% | Sep 27, 2019 | When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved ... |
| CVE-2019-8074 | CRITICAL | 9.8 | 18.9% | Sep 27, 2019 | ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Path Traversal vulnerability. Su... |
| CVE-2019-8073 | CRITICAL | 9.8 | 8.3% | Sep 27, 2019 | ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable... |
| CVE-2019-16920 | CRITICAL | 9.8 | 100.0% | Sep 27, 2019 | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i... |
| CVE-2019-16915 | CRITICAL | 9.8 | 3.7% | Sep 26, 2019 | An issue was discovered in pfSense through 2.4.4-p3. widgets/widgets/picture.widget.php uses the widgetkey parameter dir... |
| CVE-2019-16894 | CRITICAL | 9.8 | 3.0% | Sep 26, 2019 | download.php in inoERP 4.15 allows SQL injection through insecure deserialization. |
| CVE-2019-16755 | CRITICAL | 9.8 | 2.5% | Sep 26, 2019 | BMC Remedy ITSM Suite is prone to unspecified vulnerabilities in both DWP and SmartIT components, which can permit remot... |
| CVE-2019-10082 | CRITICAL | 9.1 | 16.5% | Sep 26, 2019 | In Apache HTTP Server 2.4.18-2.4.39, using fuzzed network input, the http/2 session handling could be made to read memor... |
| CVE-2019-15941 | CRITICAL | 9.8 | 2.2% | Sep 25, 2019 | OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a craf... |
| CVE-2019-15069 | CRITICAL | 9.8 | 1.5% | Sep 25, 2019 | An unsafe authentication interface was discovered in Smart Battery A4, a multifunctional portable charger, firmware vers... |
| CVE-2019-15068 | CRITICAL | 9.8 | 1.9% | Sep 25, 2019 | A broken access control vulnerability in Smart Battery A4, a multifunctional portable charger, firmware version ?<= r1.7... |
| CVE-2019-15067 | CRITICAL | 9.8 | 1.9% | Sep 25, 2019 | An authentication bypass vulnerability discovered in Smart Battery A2-25DE, a multifunctional portable charger, firmware... |
| CVE-2019-12204 | CRITICAL | 9.8 | 1.5% | Sep 25, 2019 | In SilverStripe through 4.3.3, a missing warning about leaving install.php in a public webroot can lead to unauthenticat... |
| CVE-2019-16881 | CRITICAL | 9.8 | 2.5% | Sep 25, 2019 | An issue was discovered in the portaudio-rs crate through 0.3.1 for Rust. There is a use-after-free with resultant arbit... |
| CVE-2019-16880 | CRITICAL | 9.8 | 1.7% | Sep 25, 2019 | An issue was discovered in the linea crate through 0.9.4 for Rust. There is double free in the Matrix::zip_elements meth... |
| CVE-2019-16194 | CRITICAL | 9.8 | 1.6% | Sep 25, 2019 | SQL injection vulnerabilities in Centreon through 19.04 allow attacks via the svc_id parameter in include/monitoring/sta... |
| CVE-2019-10418 | CRITICAL | 9.9 | 1.2% | Sep 25, 2019 | Jenkins Kubernetes :: Pipeline :: Arquillian Steps Plugin provides a custom whitelist for script security that allowed a... |
| CVE-2019-10417 | CRITICAL | 9.9 | 1.2% | Sep 25, 2019 | Jenkins Kubernetes :: Pipeline :: Kubernetes Steps Plugin provides a custom whitelist for script security that allowed a... |
| CVE-2019-16868 | CRITICAL | 9.8 | 2.6% | Sep 25, 2019 | emlog through 6.0.0beta has an arbitrary file deletion vulnerability via an admin/data.php?action=dell_all_bak request w... |
| CVE-2019-16759 | CRITICAL | 9.8 | 99.7% | Sep 24, 2019 | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge... |
| CVE-2019-16724 | CRITICAL | 9.8 | 72.2% | Sep 24, 2019 | File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti... |
| CVE-2019-5505 | CRITICAL | 9.8 | 0.8% | Sep 24, 2019 | ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. |
| CVE-2019-5504 | CRITICAL | 9.8 | 2.0% | Sep 24, 2019 | ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowin... |
| CVE-2019-16411 | CRITICAL | 9.8 | 2.0% | Sep 24, 2019 | An issue was discovered in Suricata 4.1.4. By sending multiple IPv4 packets that have invalid IPv4Options, the function ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now