2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20406 | HIGH | 7.8 | 0.5% | Feb 6, 2020 | The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0... |
| CVE-2019-20400 | HIGH | 7.8 | 0.4% | Feb 6, 2020 | The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directo... |
| CVE-2019-20104 | HIGH | 7.5 | 2.4% | Feb 6, 2020 | The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 before 3.7.1 allows remote... |
| CVE-2019-12180 | HIGH | 7.8 | 4.6% | Feb 5, 2020 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, th... |
| CVE-2019-11516 | HIGH | 8.1 | 0.9% | Feb 5, 2020 | An issue was discovered in the Bluetooth component of the Cypress (formerly owned by Broadcom) Wireless IoT codebase. Ex... |
| CVE-2019-4613 | HIGH | 8.8 | 0.5% | Feb 5, 2020 | IBM Planning Analytics 2.0 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2019-16204 | HIGH | 7.5 | 1.5% | Feb 5, 2020 | Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets ... |
| CVE-2019-16203 | HIGH | 7.5 | 1.4% | Feb 5, 2020 | Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these ... |
| CVE-2019-12528 | HIGH | 7.5 | 10.5% | Feb 4, 2020 | An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive informat... |
| CVE-2019-15613 | HIGH | 8 | 1.1% | Feb 4, 2020 | A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking... |
| CVE-2019-4541 | HIGH | 7.2 | 1.3% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses incomplete blacklisting for input validation which allows attackers to bypass a... |
| CVE-2019-4540 | HIGH | 7.5 | 0.8% | Feb 4, 2020 | IBM Security Directory Server 6.4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to d... |
| CVE-2019-19273 | HIGH | 7.8 | 0.2% | Feb 4, 2020 | On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL... |
| CVE-2019-9674 | HIGH | 7.5 | 5.5% | Feb 4, 2020 | Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a... |
| CVE-2019-9502 | HIGH | 8.8 | 2.4% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. If the vendor information element data length is la... |
| CVE-2019-9501 | HIGH | 8.8 | 2.9% | Feb 3, 2020 | The Broadcom wl WiFi driver is vulnerable to a heap buffer overflow. By supplying a vendor information element with a da... |
| CVE-2019-16893 | HIGH | 7.5 | 37.8% | Feb 3, 2020 | The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the... |
| CVE-2019-18193 | HIGH | 7.5 | 0.3% | Feb 3, 2020 | In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain co... |
| CVE-2019-13000 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states... |
| CVE-2019-12999 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. |
| CVE-2019-12998 | HIGH | 7.5 | 1.8% | Jan 31, 2020 | c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md ... |
| CVE-2019-4720 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia... |
| CVE-2019-19550 | HIGH | 7.5 | 1.9% | Jan 31, 2020 | Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of a... |
| CVE-2019-20358 | HIGH | 7.8 | 4.6% | Jan 30, 2020 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to... |
| CVE-2019-18634 | HIGH | 7.8 | 19.4% | Jan 29, 2020 | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now