2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15000 | CRITICAL | 9.8 | 7.8% | Sep 19, 2019 | The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6... |
| CVE-2019-3689 | CRITICAL | 9.8 | 1.5% | Sep 19, 2019 | The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux En... |
| CVE-2019-3758 | CRITICAL | 9.8 | 1.5% | Sep 18, 2019 | RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allo... |
| CVE-2019-11211 | CRITICAL | 9.9 | 3.7% | Sep 18, 2019 | The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analyt... |
| CVE-2019-11210 | CRITICAL | 10 | 3.7% | Sep 18, 2019 | The server component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, and TIBCO Spotfire Analyt... |
| CVE-2019-13558 | CRITICAL | 9.8 | 2.9% | Sep 18, 2019 | In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of ... |
| CVE-2019-5067 | CRITICAL | 9.8 | 3.4% | Sep 18, 2019 | An uninitialized memory access vulnerability exists in the way Aspose.PDF 19.2 for C++ handles invalid parent object poi... |
| CVE-2019-5066 | CRITICAL | 9.8 | 2.4% | Sep 18, 2019 | An exploitable use-after-free vulnerability exists in the way LZW-compressed streams are processed in Aspose.PDF 19.2 fo... |
| CVE-2019-15301 | CRITICAL | 9.8 | 1.5% | Sep 18, 2019 | A SQL injection vulnerability in the method Terrasoft.Core.DB.Column.Const() in Terrasoft Bpm'online CRM-System SDK 7.13... |
| CVE-2019-13550 | CRITICAL | 9.8 | 2.8% | Sep 18, 2019 | In WebAccess, versions 8.4.1 and prior, an improper authorization vulnerability may allow an attacker to disclose sensit... |
| CVE-2019-9677 | CRITICAL | 9.8 | 1.1% | Sep 18, 2019 | The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer ov... |
| CVE-2019-14254 | CRITICAL | 9.8 | 1.5% | Sep 18, 2019 | An issue was discovered in the secure portal in Publisure 2.1.2. Because SQL queries are not well sanitized, there are m... |
| CVE-2019-16399 | CRITICAL | 9.8 | 7.1% | Sep 18, 2019 | Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce... |
| CVE-2019-16199 | CRITICAL | 9.8 | 13.1% | Sep 17, 2019 | eQ-3 Homematic CCU2 before 2.47.18 and CCU3 before 3.47.18 allow Remote Code Execution by unauthenticated attackers with... |
| CVE-2019-6840 | CRITICAL | 9.8 | 1.1% | Sep 17, 2019 | A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.m... |
| CVE-2019-6837 | CRITICAL | 9.1 | 1.0% | Sep 17, 2019 | A Server-Side Request Forgery (SSRF): CWE-918 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX serve... |
| CVE-2019-16378 | CRITICAL | 9.8 | 2.5% | Sep 17, 2019 | OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: a... |
| CVE-2019-16239 | CRITICAL | 9.8 | 3.4% | Sep 17, 2019 | process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encodin... |
| CVE-2019-15131 | CRITICAL | 9.8 | 1.9% | Sep 17, 2019 | In Code42 Enterprise 6.7.5 and earlier, 6.8.4 through 6.8.8, and 7.0.0 a vulnerability has been identified that may allo... |
| CVE-2019-5482 | CRITICAL | 9.8 | 17.9% | Sep 16, 2019 | Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3. |
| CVE-2019-5481 | CRITICAL | 9.8 | 7.3% | Sep 16, 2019 | Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. |
| CVE-2019-15741 | CRITICAL | 9.8 | 3.1% | Sep 16, 2019 | An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a pri... |
| CVE-2019-10071 | CRITICAL | 9.8 | 8.8% | Sep 16, 2019 | The code which checks HMAC in form submissions used String.equals() for comparisons, which results in a timing side chan... |
| CVE-2019-16366 | CRITICAL | 9.8 | 1.4% | Sep 16, 2019 | In XS 9.0.0 in Moddable SDK OS180329, there is a heap-based buffer overflow in fxBeginHost in xsAPI.c when called from f... |
| CVE-2019-0195 | CRITICAL | 9.8 | 14.9% | Sep 16, 2019 | Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it do... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now