2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10074 | CRITICAL | 9.8 | 3.4% | Sep 11, 2019 | An RCE is possible by entering Freemarker markup in an Apache OFBiz Form Widget textarea field when encoding has been di... |
| CVE-2019-0189 | CRITICAL | 9.8 | 23.7% | Sep 11, 2019 | The java.io.ObjectInputStream is known to cause Java serialisation issues. This issue here is exposed by the "webtools/c... |
| CVE-2019-13473 | CRITICAL | 9.8 | 4.4% | Sep 11, 2019 | TELESTAR Bobs Rock Radio, Dabman D10, Dabman i30 Stereo, Imperial i110, Imperial i150, Imperial i200, Imperial i200-cd, ... |
| CVE-2019-16227 | CRITICAL | 9.8 | 2.0% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invali... |
| CVE-2019-16225 | CRITICAL | 9.8 | 1.8% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_... |
| CVE-2019-16224 | CRITICAL | 9.8 | 1.8% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy ... |
| CVE-2019-10256 | CRITICAL | 9.8 | 1.3% | Sep 10, 2019 | An authentication bypass vulnerability in VIVOTEK IPCam versions prior to 0x13a was found. |
| CVE-2019-14457 | CRITICAL | 9.8 | 2.6% | Sep 10, 2019 | VIVOTEK IP Camera devices with firmware before 0x20x have a stack-based buffer overflow via a crafted HTTP header. |
| CVE-2019-11496 | CRITICAL | 9.1 | 1.4% | Sep 10, 2019 | In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and writ... |
| CVE-2019-11495 | CRITICAL | 9.8 | 2.1% | Sep 10, 2019 | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server use... |
| CVE-2019-3975 | CRITICAL | 9.8 | 4.6% | Sep 10, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.1 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-15896 | CRITICAL | 9.8 | 7.5% | Sep 10, 2019 | An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.ll... |
| CVE-2019-16192 | CRITICAL | 9.8 | 2.1% | Sep 9, 2019 | upload_model() in /admini/controllers/system/managemodel.php in DocCms 2016.5.17 allow remote attackers to execute arbit... |
| CVE-2019-16184 | CRITICAL | 9.8 | 1.7% | Sep 9, 2019 | A CSV injection vulnerability was found in Limesurvey before 3.17.14 that allows survey participants to inject commands ... |
| CVE-2019-6960 | CRITICAL | 9.8 | 2.1% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6... |
| CVE-2019-16190 | CRITICAL | 9.8 | 2.7% | Sep 9, 2019 | SharePort Web Access on D-Link DIR-868L REVB through 2.03, DIR-885L REVA through 1.20, and DIR-895L REVA through 1.21 de... |
| CVE-2019-12405 | CRITICAL | 9.8 | 3.5% | Sep 9, 2019 | Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in t... |
| CVE-2019-16114 | CRITICAL | 9.8 | 4.8% | Sep 9, 2019 | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted databas... |
| CVE-2019-10668 | CRITICAL | 9.1 | 1.6% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not en... |
| CVE-2019-10665 | CRITICAL | 9.8 | 1.5% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/com... |
| CVE-2019-16143 | CRITICAL | 9.8 | 0.9% | Sep 9, 2019 | An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HM... |
| CVE-2019-16142 | CRITICAL | 9.8 | 1.8% | Sep 9, 2019 | An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable re... |
| CVE-2019-16140 | CRITICAL | 9.8 | 1.6% | Sep 9, 2019 | An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion. |
| CVE-2019-16139 | CRITICAL | 9.8 | 1.9% | Sep 9, 2019 | An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-... |
| CVE-2019-16138 | CRITICAL | 9.8 | 2.5% | Sep 9, 2019 | An issue was discovered in the image crate before 0.21.3 for Rust, affecting the HDR image format decoder. Vec::set_len ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now