2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13054 | — | — | 0.8% | Jun 29, 2019 | The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Win... |
| CVE-2019-13053 | — | — | 0.5% | Jun 29, 2019 | Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combina... |
| CVE-2019-13052 | — | — | 0.7% | Jun 29, 2019 | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. |
| CVE-2019-13050 | HIGH | 7.5 | 2.7% | Jun 29, 2019 | Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes i... |
| CVE-2019-13049 | — | — | 0.5% | Jun 29, 2019 | An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland proc... |
| CVE-2019-13048 | — | — | 0.4% | Jun 29, 2019 | kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allo... |
| CVE-2019-13047 | — | — | 0.5% | Jun 29, 2019 | kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SET... |
| CVE-2019-13046 | — | — | 0.5% | Jun 29, 2019 | linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications. |
| CVE-2019-13045 | — | — | 3.3% | Jun 29, 2019 | Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending ... |
| CVE-2019-13044 | — | — | — | Jun 29, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13038 | MEDIUM | 6.1 | 1.4% | Jun 29, 2019 | mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the /... |
| CVE-2019-13035 | — | — | 0.4% | Jun 29, 2019 | Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFM... |
| CVE-2019-13032 | — | — | 1.0% | Jun 28, 2019 | An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or... |
| CVE-2019-13031 | — | — | 1.9% | Jun 28, 2019 | LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification se... |
| CVE-2019-13028 | — | — | 3.7% | Jun 28, 2019 | An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.... |
| CVE-2019-10993 | CRITICAL | 9.8 | 10.7% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote a... |
| CVE-2019-10991 | CRITICAL | 9.8 | 9.0% | Jun 28, 2019 | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack ... |
| CVE-2019-10989 | CRITICAL | 9.8 | 8.6% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of... |
| CVE-2019-10987 | HIGH | 8.8 | 5.7% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple out-of-bounds write vulnerabilities are caused by a lack of proper... |
| CVE-2019-10985 | CRITICAL | 9.1 | 3.1% | Jun 28, 2019 | In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of... |
| CVE-2019-10983 | HIGH | 7.5 | 2.4% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, an out-of-bounds read vulnerability is caused by a lack of proper validatio... |
| CVE-2019-10964 | HIGH | 7.1 | 1.2% | Jun 28, 2019 | Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood gluc... |
| CVE-2019-10175 | MEDIUM | 6.5 | 1.0% | Jun 28, 2019 | A flaw was found in the containerized-data-importer in virt-cdi-cloner, version 1.4, where the host-assisted cloning fea... |
| CVE-2019-9843 | — | — | 1.5% | Jun 28, 2019 | In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would re... |
| CVE-2019-12932 | — | — | 0.8% | Jun 28, 2019 | A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete sear... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now