2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-16264CRITICAL9.8In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username param...
CVE-2019-16057CRITICAL9.8The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
CVE-2019-13474CRITICAL9.8TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, ...
CVE-2019-16335CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar...
CVE-2019-14540CRITICAL9.8A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikar...
CVE-2019-16314CRITICAL9.8Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2.
CVE-2019-16309CRITICAL9.8FlameCMS 3.3.5 has SQL injection in account/login.php via accountName.
CVE-2019-16303CRITICAL9.8A class generated by the Generator in JHipster before 6.3.0 and JHipster Kotlin through 1.1.0 produces code that uses an...
CVE-2019-5485CRITICAL10NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje...
CVE-2019-13923CRITICAL9.6A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration ...
CVE-2019-13918CRITICAL9.8A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0 SP1). The web interface has no ...
CVE-2019-13548CRITICAL9.8CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https reque...
CVE-2019-13364CRITICAL9.6admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat&#95;number, billing&#95;name, company, or billing&#95...
CVE-2019-13363CRITICAL9.6admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm&#95;send&#95;html&#95;mail, nbm&#95;send&#95;mai...
CVE-2019-8070CRITICAL9.8Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability....
CVE-2019-8069CRITICAL9.8Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution ...
CVE-2019-11898CRITICAL9.9Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The serv...
CVE-2019-14237CRITICAL9.8On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method...
CVE-2019-14236CRITICAL9.8On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protec...
CVE-2019-6005CRITICAL9.8Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary op...
CVE-2019-3638CRITICAL9.6Reflected Cross Site Scripting vulnerability in Administrators web console in McAfee Web Gateway (MWG) 7.8.x prior to 7....
CVE-2019-16261CRITICAL9.1Tripp Lite PDUMH15AT 12.04.0053 and SU750XL 12.04.0052 devices allow unauthenticated POST requests to the /Forms/ direct...
CVE-2019-16257CRITICAL9.8Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote at...
CVE-2019-16256CRITICAL9.8Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote att...
CVE-2019-1306CRITICAL9.8A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to val...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now