2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15010 | HIGH | 8.8 | 2.6% | Jan 15, 2020 | Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0... |
| CVE-2019-18271 | HIGH | 8.8 | 0.6% | Jan 15, 2020 | OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request f... |
| CVE-2019-9510 | HIGH | 7.8 | 1.3% | Jan 15, 2020 | A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne... |
| CVE-2019-16469 | HIGH | 7.5 | 17.2% | Jan 15, 2020 | Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. ... |
| CVE-2019-16468 | HIGH | 7.5 | 2.6% | Jan 15, 2020 | Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Succe... |
| CVE-2019-18412 | HIGH | 7.5 | 1.0% | Jan 15, 2020 | JetBrains IDETalk plugin before version 193.4099.10 allows XXE |
| CVE-2019-16784 | HIGH | 7.8 | 0.7% | Jan 14, 2020 | In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic... |
| CVE-2019-13537 | HIGH | 7.5 | 1.3% | Jan 14, 2020 | The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffe... |
| CVE-2019-19548 | HIGH | 7.8 | 0.4% | Jan 14, 2020 | Norton Power Eraser, prior to 5.3.0.67, may be susceptible to a privilege escalation vulnerability, which is a type of i... |
| CVE-2019-10995 | HIGH | 8.8 | 0.7% | Jan 14, 2020 | ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during t... |
| CVE-2019-12399 | HIGH | 7.5 | 3.9% | Jan 14, 2020 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more ... |
| CVE-2019-19680 | HIGH | 8.8 | 1.1% | Jan 13, 2020 | A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P... |
| CVE-2019-19728 | HIGH | 7.5 | 1.3% | Jan 13, 2020 | SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. |
| CVE-2019-20209 | HIGH | 7.5 | 3.2% | Jan 13, 2020 | The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure ... |
| CVE-2019-18894 | HIGH | 7.8 | 1.8% | Jan 13, 2020 | In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast... |
| CVE-2019-19475 | HIGH | 8.8 | 2.6% | Jan 10, 2020 | An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-i... |
| CVE-2019-13767 | HIGH | 8.8 | 15.5% | Jan 10, 2020 | Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the ... |
| CVE-2019-18194 | HIGH | 7.8 | 2.2% | Jan 10, 2020 | TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio... |
| CVE-2019-14306 | HIGH | 7.5 | 1.4% | Jan 10, 2020 | Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2). |
| CVE-2019-14304 | HIGH | 8.8 | 0.7% | Jan 10, 2020 | Ricoh SP C250DN 1.06 devices allow CSRF. |
| CVE-2019-14301 | HIGH | 7.5 | 1.4% | Jan 10, 2020 | Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2). |
| CVE-2019-19820 | HIGH | 7.8 | 0.7% | Jan 10, 2020 | An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an ... |
| CVE-2019-4508 | HIGH | 7.8 | 0.3% | Jan 10, 2020 | IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local a... |
| CVE-2019-20373 | HIGH | 7.8 | 0.4% | Jan 9, 2020 | LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the ... |
| CVE-2019-20184 | HIGH | 7.8 | 1.6% | Jan 9, 2020 | KeePass 2.4.1 allows CSV injection in the title field of a CSV export. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now