2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1913 | CRITICAL | 9.8 | 25.9% | Aug 7, 2019 | Multiple vulnerabilities in the web management interface of Cisco Small Business 220 Series Smart Switches could allow a... |
| CVE-2019-1912 | CRITICAL | 9.1 | 17.0% | Aug 7, 2019 | A vulnerability in the web management interface of Cisco Small Business 220 Series Smart Switches could allow an unauthe... |
| CVE-2019-14697 | CRITICAL | 9.8 | 2.5% | Aug 6, 2019 | musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In s... |
| CVE-2019-14695 | CRITICAL | 9.8 | 2.7% | Aug 6, 2019 | A SQL injection vulnerability exists in the Sygnoos Popup Builder plugin before 3.45 for WordPress. Successful exploitat... |
| CVE-2019-9141 | CRITICAL | 9.8 | 2.4% | Aug 2, 2019 | ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers ... |
| CVE-2019-14532 | CRITICAL | 9.8 | 2.1% | Aug 2, 2019 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/has... |
| CVE-2019-14529 | CRITICAL | 9.8 | 28.1% | Aug 2, 2019 | OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. |
| CVE-2019-10938 | CRITICAL | 9.8 | 1.5% | Aug 2, 2019 | A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 dev... |
| CVE-2019-14495 | CRITICAL | 9.8 | 1.9% | Aug 1, 2019 | webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface. |
| CVE-2019-13572 | CRITICAL | 9.8 | 2.2% | Aug 1, 2019 | The Adenion Blog2Social plugin through 5.5.0 for WordPress allows SQL Injection. |
| CVE-2019-14463 | CRITICAL | 9.1 | 1.9% | Jul 31, 2019 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_... |
| CVE-2019-14462 | CRITICAL | 9.1 | 2.0% | Jul 31, 2019 | An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_... |
| CVE-2019-12797 | CRITICAL | 9.8 | 1.2% | Jul 31, 2019 | A clone version of an ELM327 OBD2 Bluetooth device has a hardcoded PIN, leading to arbitrary commands to an OBD-II bus o... |
| CVE-2019-5454 | CRITICAL | 9.8 | 2.0% | Jul 30, 2019 | SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query i... |
| CVE-2019-14313 | CRITICAL | 9.8 | 4.5% | Jul 30, 2019 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat... |
| CVE-2019-14431 | CRITICAL | 9.8 | 3.6% | Jul 29, 2019 | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based... |
| CVE-2019-14271 | CRITICAL | 9.8 | 18.8% | Jul 29, 2019 | In Docker 19.03.x before 19.03.1 linked against the GNU C Library (aka glibc), code injection can occur when the nsswitc... |
| CVE-2019-13571 | CRITICAL | 9.8 | 4.0% | Jul 29, 2019 | A SQL injection vulnerability exists in the Vsourz Digital Advanced CF7 DB plugin through 1.6.1 for WordPress. Successfu... |
| CVE-2019-14379 | CRITICAL | 9.8 | 8.0% | Jul 29, 2019 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (becau... |
| CVE-2019-13990 | CRITICAL | 9.8 | 16.6% | Jul 26, 2019 | initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attack... |
| CVE-2019-14277 | CRITICAL | 9.8 | 7.3% | Jul 26, 2019 | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticat... |
| CVE-2019-5604 | CRITICAL | 9.6 | 3.1% | Jul 26, 2019 | In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE bef... |
| CVE-2019-10744 | CRITICAL | 9.1 | 5.0% | Jul 26, 2019 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked ... |
| CVE-2019-9885 | CRITICAL | 9.8 | 2.6% | Jul 25, 2019 | eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php Studen... |
| CVE-2019-9884 | CRITICAL | 9.8 | 3.0% | Jul 25, 2019 | eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password vali... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now