2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5497 | — | — | 2.9% | Jul 1, 2019 | NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default acc... |
| CVE-2019-10979 | — | — | 3.4% | Jul 1, 2019 | SICK MSC800 all versions prior to Version 4.0, the affected firmware versions contain a hard-coded customer account pass... |
| CVE-2019-7278 | — | — | 1.5% | Jul 1, 2019 | Optergy Proton/Enterprise devices have an Unauthenticated SMS Sending Service. |
| CVE-2019-7277 | — | — | 1.9% | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Unauthenticated Internal Network Information Disclosure. |
| CVE-2019-7276 | — | — | 93.4% | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console. |
| CVE-2019-7275 | MEDIUM | 6.1 | 9.1% | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Open Redirect. |
| CVE-2019-3962 | — | — | 1.0% | Jul 1, 2019 | Content Injection vulnerability in Tenable Nessus prior to 8.5.0 may allow an authenticated, local attacker to exploit t... |
| CVE-2019-13137 | MEDIUM | 6.5 | 1.9% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadPSImage in coders/ps.c. |
| CVE-2019-13136 | — | — | 1.5% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c. |
| CVE-2019-13135 | HIGH | 8.8 | 3.3% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.... |
| CVE-2019-13134 | MEDIUM | 5.5 | 1.1% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadVIFFImage in coders/viff.c. |
| CVE-2019-13133 | MEDIUM | 5.5 | 1.1% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a memory leak vulnerability in the function ReadBMPImage in coders/bmp.c. |
| CVE-2019-7670 | HIGH | 7.2 | 18.3% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo... |
| CVE-2019-7669 | HIGH | 8.8 | 31.4% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allo... |
| CVE-2019-7668 | — | — | 1.6% | Jul 1, 2019 | Prima Systems FlexAir devices have Default Credentials. |
| CVE-2019-7667 | CRITICAL | 9.8 | 4.5% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application generates database backup files with a predictable nam... |
| CVE-2019-7666 | HIGH | 8.8 | 14.8% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu... |
| CVE-2019-7281 | HIGH | 8.8 | 0.9% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may a... |
| CVE-2019-7280 | HIGH | 8.8 | 2.4% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by br... |
| CVE-2019-7279 | — | — | 1.8% | Jul 1, 2019 | Optergy Proton/Enterprise devices have Hard-coded Credentials. |
| CVE-2019-1578 | — | — | 1.1% | Jul 1, 2019 | Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker... |
| CVE-2019-1577 | — | — | 0.9% | Jul 1, 2019 | Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject... |
| CVE-2019-13024 | — | — | 32.2% | Jul 1, 2019 | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra... |
| CVE-2019-12826 | — | — | 1.1% | Jul 1, 2019 | A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 ... |
| CVE-2019-13131 | — | — | 3.6% | Jul 1, 2019 | Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now