2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4336 | CRITICAL | 9.8 | 2.0% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 uses an inadequate account lockout setting that could allow a... |
| CVE-2019-13107 | CRITICAL | 9.8 | 1.8% | Jun 30, 2019 | Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c |
| CVE-2019-11829 | CRITICAL | 9.8 | 2.2% | Jun 30, 2019 | OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote ... |
| CVE-2019-11821 | CRITICAL | 9.8 | 1.7% | Jun 30, 2019 | SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 ... |
| CVE-2019-10993 | CRITICAL | 9.8 | 10.7% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple untrusted pointer dereference vulnerabilities may allow a remote a... |
| CVE-2019-10991 | CRITICAL | 9.8 | 9.0% | Jun 28, 2019 | In WebAccess/SCADA, Versions 8.3.5 and prior, multiple stack-based buffer overflow vulnerabilities are caused by a lack ... |
| CVE-2019-10989 | CRITICAL | 9.8 | 8.6% | Jun 28, 2019 | In WebAccess/SCADA Versions 8.3.5 and prior, multiple heap-based buffer overflow vulnerabilities are caused by a lack of... |
| CVE-2019-10985 | CRITICAL | 9.1 | 3.1% | Jun 28, 2019 | In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of... |
| CVE-2019-1620 | CRITICAL | 9.8 | 83.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-1619 | CRITICAL | 9.8 | 82.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-6168 | CRITICAL | 9.8 | 2.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. |
| CVE-2019-6167 | CRITICAL | 9.8 | 2.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. |
| CVE-2019-1848 | CRITICAL | 9.3 | 0.7% | Jun 20, 2019 | A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to ... |
| CVE-2019-2729 | CRITICAL | 9.8 | 88.8% | Jun 19, 2019 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte... |
| CVE-2019-12900 | CRITICAL | 9.8 | 8.0% | Jun 19, 2019 | BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors. |
| CVE-2019-11040 | CRITICAL | 9.1 | 4.0% | Jun 19, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11039 | CRITICAL | 9.1 | 3.0% | Jun 19, 2019 | Function iconv_mime_decode_headers() in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6 may pe... |
| CVE-2019-5016 | CRITICAL | 9.1 | 3.6% | Jun 17, 2019 | An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module which enables the ReadyS... |
| CVE-2019-6327 | CRITICAL | 9.8 | 2.4% | Jun 17, 2019 | HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer s... |
| CVE-2019-10126 | CRITICAL | 9.8 | 6.8% | Jun 14, 2019 | A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net... |
| CVE-2019-11119 | CRITICAL | 9.8 | 2.0% | Jun 13, 2019 | Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticat... |
| CVE-2019-6580 | CRITICAL | 9.8 | 1.7% | Jun 12, 2019 | A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All ver... |
| CVE-2019-3888 | CRITICAL | 9.8 | 3.4% | Jun 12, 2019 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials throug... |
| CVE-2019-3412 | CRITICAL | 9.8 | 2.9% | Jun 11, 2019 | All versions up to BD_R218V2.4 of ZTE MF920 product are impacted by command execution vulnerability. Due to some interfa... |
| CVE-2019-3409 | CRITICAL | 9 | 1.9% | Jun 11, 2019 | All versions up to UKBB_WF820+_1.0.0B06 of ZTE WF820+ LTE Outdoor CPE product are impacted by command injection vulnerab... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now