2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14002 | HIGH | 7.8 | 0.2% | Feb 7, 2020 | APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in ... |
| CVE-2019-10567 | HIGH | 7.8 | 0.2% | Feb 7, 2020 | There is a way to deceive the GPU kernel driver into thinking there is room in the GPU ringbuffer and overwriting existi... |
| CVE-2019-15711 | HIGH | 7.8 | 0.5% | Feb 6, 2020 | A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to ru... |
| CVE-2019-20406 | HIGH | 7.8 | 0.5% | Feb 6, 2020 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0... |
| CVE-2019-20400 | HIGH | 7.8 | 0.4% | Feb 6, 2020 | The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directo... |
| CVE-2019-20104 | HIGH | 7.5 | 2.4% | Feb 6, 2020 | The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote... |
| CVE-2019-12180 | HIGH | 7.8 | 4.6% | Feb 5, 2020 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th... |
| CVE-2019-11516 | HIGH | 8.1 | 0.9% | Feb 5, 2020 | An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Ex... |
| CVE-2019-4613 | HIGH | 8.8 | 0.5% | Feb 5, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2019-16204 | HIGH | 7.5 | 1.5% | Feb 5, 2020 | Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets ... |
| CVE-2019-16203 | HIGH | 7.5 | 1.4% | Feb 5, 2020 | Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these ... |
| CVE-2019-12528 | HIGH | 7.5 | 10.5% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive informat... |
| CVE-2019-15613 | HIGH | 8 | 1.1% | Feb 4, 2020 | A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking... |
| CVE-2019-4541 | HIGH | 7.2 | 1.3% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass a... |
| CVE-2019-4540 | HIGH | 7.5 | 0.8% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to d... |
| CVE-2019-19273 | HIGH | 7.8 | 0.2% | Feb 4, 2020 | On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL... |
| CVE-2019-9674 | HIGH | 7.5 | 5.5% | Feb 4, 2020 | Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a... |
| CVE-2019-9502 | HIGH | 8.8 | 2.4% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is la... |
| CVE-2019-9501 | HIGH | 8.8 | 2.9% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a da... |
| CVE-2019-16893 | HIGH | 7.5 | 37.8% | Feb 3, 2020 | The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the... |
| CVE-2019-18193 | HIGH | 7.5 | 0.3% | Feb 3, 2020 | In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain co... |
| CVE-2019-13000 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states... |
| CVE-2019-12999 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. |
| CVE-2019-12998 | HIGH | 7.5 | 1.8% | Jan 31, 2020 | c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md ... |
| CVE-2019-4720 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now