2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7107 | CRITICAL | 9.8 | 27.8% | May 23, 2019 | Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation coul... |
| CVE-2019-7106 | — | — | 8.3% | May 23, 2019 | Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary ... |
| CVE-2019-7105 | — | — | 8.3% | May 23, 2019 | Adobe XD versions 16.0 and earlier have a path traversal vulnerability. Successful exploitation could lead to arbitrary ... |
| CVE-2019-7104 | — | — | 5.1% | May 23, 2019 | Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation c... |
| CVE-2019-7097 | — | — | 3.6% | May 23, 2019 | Adobe Dreamweaver versions 19.0 and earlier have an insecure protocol implementation vulnerability. Successful exploitat... |
| CVE-2019-12301 | — | — | 2.0% | May 23, 2019 | The Percona Server 5.6.44-85.0-1 packages for Debian and Ubuntu suffered an issue where the server would reset the root ... |
| CVE-2019-12300 | — | — | 1.8% | May 23, 2019 | Buildbot before 1.8.2 and 2.x before 2.3.1 accepts a user-submitted authorization token from OAuth and uses it to authen... |
| CVE-2019-12272 | — | — | 7.4% | May 23, 2019 | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_st... |
| CVE-2019-9949 | — | — | 3.1% | May 23, 2019 | Western Digital My Cloud Cloud, Mirror Gen2, EX2 Ultra, EX2100, EX4100, DL2100, DL4100, PR2100 and PR4100 before firmwar... |
| CVE-2019-4078 | HIGH | 7.8 | 0.4% | May 23, 2019 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute co... |
| CVE-2019-4039 | MEDIUM | 5.5 | 0.3% | May 23, 2019 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local attacker to cause a denial of ser... |
| CVE-2019-12298 | — | — | 1.1% | May 23, 2019 | Leanify 0.4.3 allows remote attackers to trigger an out-of-bounds write (1024 bytes) via a modified input file. |
| CVE-2019-12297 | — | — | 1.7% | May 23, 2019 | An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Fo... |
| CVE-2019-12042 | — | — | 3.6% | May 23, 2019 | Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSh... |
| CVE-2019-10977 | HIGH | 7.5 | 3.5% | May 23, 2019 | In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send... |
| CVE-2019-0201 | MEDIUM | 5.9 | 9.6% | May 23, 2019 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command does... |
| CVE-2019-11873 | CRITICAL | 9.8 | 8.8% | May 23, 2019 | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client ... |
| CVE-2019-12295 | HIGH | 7.5 | 3.8% | May 23, 2019 | In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed ... |
| CVE-2019-12293 | — | — | 2.5% | May 23, 2019 | In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with ... |
| CVE-2019-6808 | CRITICAL | 9.8 | 8.2% | May 22, 2019 | A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quant... |
| CVE-2019-6807 | HIGH | 7.5 | 2.2% | May 22, 2019 | A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a... |
| CVE-2019-6806 | HIGH | 7.5 | 2.3% | May 22, 2019 | A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum,... |
| CVE-2019-6821 | MEDIUM | 6.5 | 1.9% | May 22, 2019 | CWE-330: Use of Insufficiently Random Values vulnerability, which could cause the hijacking of the TCP connection when u... |
| CVE-2019-6820 | HIGH | 8.2 | 1.2% | May 22, 2019 | A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device ... |
| CVE-2019-6819 | HIGH | 7.5 | 1.1% | May 22, 2019 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now