2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7226 | HIGH | 8.8 | 5.3% | Jun 27, 2019 | The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication a... |
| CVE-2019-7228 | HIGH | 8.8 | 3.7% | Jun 27, 2019 | The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting... |
| CVE-2019-12581 | — | — | 6.4% | Jun 27, 2019 | A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, ... |
| CVE-2019-4252 | HIGH | 7.5 | 3.4% | Jun 27, 2019 | IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directorie... |
| CVE-2019-4250 | MEDIUM | 5.4 | 0.7% | Jun 27, 2019 | IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cros... |
| CVE-2019-4249 | MEDIUM | 5.4 | 0.7% | Jun 27, 2019 | IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2019-4084 | MEDIUM | 4.3 | 1.0% | Jun 27, 2019 | IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) could allow an authen... |
| CVE-2019-4083 | MEDIUM | 5.4 | 0.7% | Jun 27, 2019 | IBM Jazz Foundation products (IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1) is vulnerable to cros... |
| CVE-2019-12887 | — | — | 1.2% | Jun 27, 2019 | KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2). |
| CVE-2019-12583 | — | — | 43.9% | Jun 27, 2019 | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attack... |
| CVE-2019-1622 | MEDIUM | 5.3 | 78.9% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-1621 | HIGH | 7.5 | 29.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-1620 | CRITICAL | 9.8 | 83.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-1619 | CRITICAL | 9.8 | 82.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-9039 | — | — | 2.7% | Jun 26, 2019 | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additio... |
| CVE-2019-10154 | HIGH | 7.5 | 1.3% | Jun 26, 2019 | A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current... |
| CVE-2019-10134 | LOW | 3.7 | 1.1% | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email... |
| CVE-2019-10133 | LOW | 3.1 | 0.9% | Jun 26, 2019 | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect f... |
| CVE-2019-12984 | — | — | 2.3% | Jun 26, 2019 | A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target() in net/nfc/netlink.c in the Linux ... |
| CVE-2019-12983 | — | — | — | Jun 26, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11884. Reason: This candidate is a reservation d... |
| CVE-2019-12982 | MEDIUM | 6.5 | 1.4% | Jun 26, 2019 | Ming (aka libming) 0.4.8 has a heap buffer overflow and underflow in the decompileCAST function in util/decompile.c in l... |
| CVE-2019-12981 | HIGH | 8.8 | 1.3% | Jun 26, 2019 | Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.... |
| CVE-2019-12980 | MEDIUM | 6.5 | 1.4% | Jun 26, 2019 | In Ming (aka libming) 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the SWFInput_readSBi... |
| CVE-2019-12979 | HIGH | 7.8 | 2.4% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/im... |
| CVE-2019-12978 | — | — | 1.9% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the ReadPANGOImage function in coders/pango.c. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now