2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16264 | CRITICAL | 9.8 | 1.5% | Sep 16, 2019 | In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username param... |
| CVE-2019-16057 | CRITICAL | 9.8 | 87.2% | Sep 16, 2019 | The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection. |
| CVE-2019-13474 | CRITICAL | 9.8 | 3.0% | Sep 16, 2019 | TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, ... |
| CVE-2019-16335 | CRITICAL | 9.8 | 4.9% | Sep 15, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar... |
| CVE-2019-14540 | CRITICAL | 9.8 | 10.7% | Sep 15, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar... |
| CVE-2019-16314 | CRITICAL | 9.8 | 38.7% | Sep 14, 2019 | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. |
| CVE-2019-16309 | CRITICAL | 9.8 | 5.0% | Sep 14, 2019 | FlameCMS 3.3.5 has SQL injection in account/login.php via accountName. |
| CVE-2019-16303 | CRITICAL | 9.8 | 3.7% | Sep 14, 2019 | A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an... |
| CVE-2019-5485 | CRITICAL | 10 | 59.8% | Sep 13, 2019 | NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje... |
| CVE-2019-13923 | CRITICAL | 9.6 | 1.1% | Sep 13, 2019 | A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration ... |
| CVE-2019-13918 | CRITICAL | 9.8 | 1.5% | Sep 13, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no ... |
| CVE-2019-13548 | CRITICAL | 9.8 | 5.9% | Sep 13, 2019 | CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque... |
| CVE-2019-13364 | CRITICAL | 9.6 | 1.4% | Sep 13, 2019 | admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_... |
| CVE-2019-13363 | CRITICAL | 9.6 | 1.4% | Sep 13, 2019 | admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mai... |
| CVE-2019-8070 | CRITICAL | 9.8 | 6.1% | Sep 12, 2019 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability.... |
| CVE-2019-8069 | CRITICAL | 9.8 | 4.5% | Sep 12, 2019 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution ... |
| CVE-2019-11898 | CRITICAL | 9.9 | 1.1% | Sep 12, 2019 | Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The serv... |
| CVE-2019-14237 | CRITICAL | 9.8 | 2.9% | Sep 12, 2019 | On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method... |
| CVE-2019-14236 | CRITICAL | 9.8 | 2.3% | Sep 12, 2019 | On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protec... |
| CVE-2019-6005 | CRITICAL | 9.8 | 2.1% | Sep 12, 2019 | Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary op... |
| CVE-2019-3638 | CRITICAL | 9.6 | 1.9% | Sep 12, 2019 | Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7.... |
| CVE-2019-16261 | CRITICAL | 9.1 | 2.8% | Sep 12, 2019 | Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ direct... |
| CVE-2019-16257 | CRITICAL | 9.8 | 2.1% | Sep 12, 2019 | Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote at... |
| CVE-2019-16256 | CRITICAL | 9.8 | 4.9% | Sep 12, 2019 | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote att... |
| CVE-2019-1306 | CRITICAL | 9.8 | 15.9% | Sep 11, 2019 | A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now