2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20213 | HIGH | 7.5 | 1.9% | Jan 2, 2020 | D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v... |
| CVE-2019-20205 | HIGH | 8.8 | 1.0% | Jan 2, 2020 | libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c. |
| CVE-2019-18568 | HIGH | 8.8 | 0.7% | Dec 31, 2019 | Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a... |
| CVE-2019-20197 | HIGH | 8.8 | 22.4% | Dec 31, 2019 | In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id pa... |
| CVE-2019-9668 | HIGH | 7.5 | 1.7% | Dec 31, 2019 | An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote... |
| CVE-2019-9197 | HIGH | 8.8 | 3.7% | Dec 31, 2019 | The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code. |
| CVE-2019-7751 | HIGH | 7.5 | 14.2% | Dec 31, 2019 | A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, for... |
| CVE-2019-20176 | HIGH | 7.5 | 4.4% | Dec 31, 2019 | In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. |
| CVE-2019-10229 | HIGH | 8.8 | 0.8% | Dec 31, 2019 | An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the dire... |
| CVE-2019-20175 | HIGH | 7.5 | 3.4% | Dec 31, 2019 | An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEM... |
| CVE-2019-20172 | HIGH | 7.8 | 0.5% | Dec 31, 2019 | Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only ... |
| CVE-2019-7479 | HIGH | 7.2 | 0.9% | Dec 31, 2019 | A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne... |
| CVE-2019-19032 | HIGH | 8.1 | 4.5% | Dec 30, 2019 | XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an ... |
| CVE-2019-19031 | HIGH | 8.1 | 5.2% | Dec 30, 2019 | Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS... |
| CVE-2019-16790 | HIGH | 8.8 | 1.2% | Dec 30, 2019 | In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only auth... |
| CVE-2019-20149 | HIGH | 7.5 | 2.3% | Dec 30, 2019 | ctorName in index.js in kind-of v6.0.2 allows external user input to overwrite certain internal attributes via a conflic... |
| CVE-2019-19470 | HIGH | 7.8 | 0.9% | Dec 30, 2019 | Unsafe usage of .NET deserialization in Named Pipe message processing allows privilege escalation to NT AUTHORITY\SYSTEM... |
| CVE-2019-13465 | HIGH | 8.6 | 1.1% | Dec 30, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3... |
| CVE-2019-20140 | HIGH | 8.8 | 1.1% | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif... |
| CVE-2019-19739 | HIGH | 7.5 | 0.7% | Dec 30, 2019 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the Secure flag on session cookies, allowing the cookie to be sent ... |
| CVE-2019-19737 | HIGH | 8.8 | 0.5% | Dec 30, 2019 | MFScripts YetiShare 3.5.2 through 4.5.3 does not set the SameSite flag on session cookies, allowing the cookie to be sen... |
| CVE-2019-19734 | HIGH | 8.8 | 1.1% | Dec 30, 2019 | _account_move_file_in_folder.ajax.php in MFScripts YetiShare 3.5.2 directly inserts values from the fileIds parameter in... |
| CVE-2019-19732 | HIGH | 7.2 | 1.1% | Dec 30, 2019 | translation_manage_text.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.3 directly inser... |
| CVE-2019-17558 | HIGH | 7.5 | 98.6% | Dec 30, 2019 | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V... |
| CVE-2019-20138 | HIGH | 7.5 | 0.8% | Dec 30, 2019 | The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for li... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now