2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16125 | CRITICAL | 9.8 | 2.2% | Sep 9, 2019 | In Jobberbase 2.0, the parameter category is not sanitized in public/page_subscribe.php, leading to /subscribe SQL injec... |
| CVE-2019-16124 | CRITICAL | 9.8 | 27.6% | Sep 9, 2019 | In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to ... |
| CVE-2019-16119 | CRITICAL | 9.8 | 25.4% | Sep 8, 2019 | SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control... |
| CVE-2019-16093 | CRITICAL | 9.8 | 1.5% | Sep 8, 2019 | Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c. |
| CVE-2019-16092 | CRITICAL | 9.8 | 1.5% | Sep 8, 2019 | Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c. |
| CVE-2019-10891 | CRITICAL | 9.8 | 19.4% | Sep 6, 2019 | An issue was discovered in D-Link DIR-806 devices. There is a command injection in function hnap_main, which calls syste... |
| CVE-2019-9855 | CRITICAL | 9.8 | 2.6% | Sep 6, 2019 | LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitra... |
| CVE-2019-13656 | CRITICAL | 9.8 | 5.8% | Sep 6, 2019 | An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.... |
| CVE-2019-14813 | CRITICAL | 9.8 | 11.4% | Sep 6, 2019 | A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly se... |
| CVE-2019-15954 | CRITICAL | 9.9 | 79.2% | Sep 5, 2019 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote... |
| CVE-2019-1976 | CRITICAL | 9.8 | 2.0% | Sep 5, 2019 | A vulnerability in the “plug-and-play” services component of Cisco Industrial Network Director (IND) could a... |
| CVE-2019-15926 | CRITICAL | 9.1 | 5.2% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.2.3. Out of bounds access exists in the functions ath6kl_wmi_pstrea... |
| CVE-2019-6644 | CRITICAL | 9.4 | 1.4% | Sep 4, 2019 | Similar to the issue identified in CVE-2018-12120, on versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, and 12.1... |
| CVE-2019-5608 | CRITICAL | 9.8 | 2.1% | Aug 30, 2019 | In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE bef... |
| CVE-2019-15780 | CRITICAL | 9.8 | 2.4% | Aug 29, 2019 | The formidable plugin before 4.02.01 for WordPress has unsafe deserialization. |
| CVE-2019-11064 | CRITICAL | 9.8 | 1.9% | Aug 29, 2019 | A vulnerability of remote credential disclosure was discovered in Advan VD-1 firmware versions up to 230. An attacker ca... |
| CVE-2019-11063 | CRITICAL | 10 | 4.5% | Aug 29, 2019 | A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22)... |
| CVE-2019-11061 | CRITICAL | 10 | 4.0% | Aug 29, 2019 | A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area... |
| CVE-2019-12643 | CRITICAL | 10 | 5.3% | Aug 28, 2019 | A vulnerability in the Cisco REST API virtual service container for Cisco IOS XE Software could allow an unauthenticated... |
| CVE-2019-4169 | CRITICAL | 9.1 | 1.7% | Aug 26, 2019 | IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC... |
| CVE-2019-14300 | CRITICAL | 9.8 | 3.1% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing HTTP cookie headers, which allow an attacker to cause a de... |
| CVE-2019-14308 | CRITICAL | 9.8 | 3.1% | Aug 26, 2019 | Several Ricoh printers have multiple buffer overflows parsing LPD packets, which allow an attacker to cause a denial of ... |
| CVE-2019-15562 | CRITICAL | 9.8 | 1.7% | Aug 26, 2019 | GORM before 1.9.10 allows SQL injection via incomplete parentheses. NOTE: Misusing Gorm by passing untrusted user input ... |
| CVE-2019-6695 | CRITICAL | 9.8 | 0.8% | Aug 23, 2019 | Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may... |
| CVE-2019-6698 | CRITICAL | 9.8 | 1.5% | Aug 23, 2019 | Use of Hard-coded Credentials vulnerability in FortiRecorder all versions below 2.7.4 may allow an unauthenticated attac... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now