2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16410 | CRITICAL | 9.1 | 2.1% | Sep 24, 2019 | An issue was discovered in Suricata 4.1.4. By sending multiple fragmented IPv4 packets, the function Defrag4Reassemble i... |
| CVE-2019-15699 | CRITICAL | 9.1 | 1.6% | Sep 24, 2019 | An issue was discovered in app-layer-ssl.c in Suricata 4.1.4. Upon receiving a corrupted SSLv3 (TLS 1.2) packet, the par... |
| CVE-2019-16383 | CRITICAL | 9.4 | 5.2% | Sep 24, 2019 | MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a... |
| CVE-2019-16748 | CRITICAL | 9.8 | 1.2% | Sep 24, 2019 | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while han... |
| CVE-2019-16746 | CRITICAL | 9.8 | 12.7% | Sep 24, 2019 | An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of va... |
| CVE-2019-16377 | CRITICAL | 9.8 | 2.6% | Sep 23, 2019 | The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control. |
| CVE-2019-3416 | CRITICAL | 9.8 | 1.1% | Sep 23, 2019 | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp... |
| CVE-2019-16722 | CRITICAL | 9.8 | 3.1% | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an s... |
| CVE-2019-16705 | CRITICAL | 9.1 | 1.7% | Sep 23, 2019 | Ming (aka libming) 0.4.8 has an out of bounds read vulnerability in the function OpCode() in the decompile.c file in lib... |
| CVE-2019-16702 | CRITICAL | 9.8 | 10.7% | Sep 23, 2019 | Integard Pro 2.2.0.9026 allows remote attackers to execute arbitrary code via a buffer overflow involving a long NoJs pa... |
| CVE-2019-16696 | CRITICAL | 9.8 | 1.9% | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit.php table parameter when action=add is used. |
| CVE-2019-16695 | CRITICAL | 9.8 | 1.9% | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter.php table parameter when action=add is used. |
| CVE-2019-16694 | CRITICAL | 9.8 | 1.9% | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/edit-result.php table parameter when action=add is used... |
| CVE-2019-16693 | CRITICAL | 9.8 | 4.3% | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/order.php table parameter when action=add is used. |
| CVE-2019-16692 | CRITICAL | 9.8 | 10.3% | Sep 22, 2019 | phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us... |
| CVE-2019-16656 | CRITICAL | 9.8 | 1.3% | Sep 21, 2019 | joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of ... |
| CVE-2019-16650 | CRITICAL | 10 | 2.2% | Sep 21, 2019 | On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has... |
| CVE-2019-16649 | CRITICAL | 10 | 0.9% | Sep 21, 2019 | On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the v... |
| CVE-2019-6650 | CRITICAL | 9.1 | 1.3% | Sep 20, 2019 | F5 BIG-IP ASM 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5... |
| CVE-2019-6649 | CRITICAL | 9.1 | 1.3% | Sep 20, 2019 | F5 BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.6.0-11.6.4, and 11.5.1-11.5.9 a... |
| CVE-2019-5521 | CRITICAL | 9.6 | 1.6% | Sep 20, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-16644 | CRITICAL | 9.8 | 1.4% | Sep 20, 2019 | App\Home\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Zhuanti/group?id= s... |
| CVE-2019-16642 | CRITICAL | 9.8 | 1.5% | Sep 20, 2019 | App\Mobile\Controller\ZhuantiController.class.php in TuziCMS 2.0.6 has SQL injection via the index.php/Mobile/Zhuanti/gr... |
| CVE-2019-15088 | CRITICAL | 9.8 | 1.7% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. Password hashes are compared using the equality operator. Thus, under speci... |
| CVE-2019-14914 | CRITICAL | 9.1 | 2.0% | Sep 20, 2019 | An issue was discovered in PRiSE adAS 1.7.0. The path is not properly escaped in the medatadata_del method, leading to a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now