2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25003 | HIGH | 7.5 | 1.4% | Dec 31, 2020 | An issue was discovered in the libsecp256k1 crate before 0.3.1 for Rust. Scalar::check_overflow allows a timing side-cha... |
| CVE-2019-25002 | CRITICAL | 9.8 | 1.5% | Dec 31, 2020 | An issue was discovered in the sodiumoxide crate before 0.2.5 for Rust. generichash::Digest::eq compares itself to itsel... |
| CVE-2019-25001 | HIGH | 7.5 | 1.4% | Dec 31, 2020 | An issue was discovered in the serde_cbor crate before 0.10.2 for Rust. The CBOR deserializer can cause stack consumptio... |
| CVE-2019-7726 | CRITICAL | 9.8 | 2.3% | Dec 31, 2020 | modules/banners/funcs/click.php in NukeViet before 4.3.04 has a SQL INSERT statement with raw header data from an HTTP r... |
| CVE-2019-7725 | CRITICAL | 9.8 | 2.5% | Dec 31, 2020 | includes/core/is_user.php in NukeViet before 4.3.04 deserializes the untrusted nvloginhash cookie (i.e., the code relies... |
| CVE-2019-20808 | MEDIUM | 6.5 | 0.3% | Dec 31, 2020 | In QEMU 4.1.0, an out-of-bounds read flaw was found in the ATI VGA implementation. It occurs in the ati_cursor_define() ... |
| CVE-2019-16747 | HIGH | 7.5 | 1.8% | Dec 30, 2020 | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and ... |
| CVE-2019-16281 | HIGH | 7.5 | 1.3% | Dec 30, 2020 | Ptarmigan before 0.2.3 lacks API token validation, e.g., an "if (token === apiToken) {return true;} return false;" code ... |
| CVE-2019-15523 | MEDIUM | 5.3 | 1.3% | Dec 30, 2020 | An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_... |
| CVE-2019-15080 | HIGH | 7.5 | 1.6% | Dec 30, 2020 | An issue was discovered in a smart contract implementation for MORPH Token through 2019-06-05, an Ethereum token. A typo... |
| CVE-2019-15079 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | A typo exists in the constructor of a smart contract implementation for EAI through 2019-06-05, an Ethereum token. This ... |
| CVE-2019-15078 | HIGH | 7.5 | 1.2% | Dec 30, 2020 | An issue was discovered in a smart contract implementation for AIRDROPX BORN through 2019-05-29, an Ethereum token. The ... |
| CVE-2019-12953 | MEDIUM | 5.3 | 1.2% | Dec 30, 2020 | Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a differe... |
| CVE-2019-12768 | CRITICAL | 9.8 | 2.3% | Dec 30, 2020 | An issue was discovered on D-Link DAP-1650 devices through v1.03b07 before 1.04B02_J65H Hot Fix. Attackers can bypass au... |
| CVE-2019-11786 | MEDIUM | 4.3 | 0.7% | Dec 22, 2020 | Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier, allows remote authentic... |
| CVE-2019-11785 | MEDIUM | 4.3 | 1.5% | Dec 22, 2020 | Improper access control in mail module (followers) in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earli... |
| CVE-2019-11784 | MEDIUM | 6.5 | 1.0% | Dec 22, 2020 | Improper access control in mail module (notifications) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and e... |
| CVE-2019-11783 | MEDIUM | 6.5 | 1.0% | Dec 22, 2020 | Improper access control in mail module (channel partners) in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 an... |
| CVE-2019-11782 | MEDIUM | 6.5 | 1.4% | Dec 22, 2020 | Improper access control in Odoo Community 14.0 and earlier and Odoo Enterprise 14.0 and earlier, allows remote authentic... |
| CVE-2019-11781 | HIGH | 8.8 | 2.1% | Dec 22, 2020 | Improper input validation in portal component in Odoo Community 12.0 and earlier and Odoo Enterprise 12.0 and earlier, a... |
| CVE-2019-16959 | MEDIUM | 6.5 | 1.6% | Dec 21, 2020 | SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. |
| CVE-2019-16957 | MEDIUM | 5.4 | 1.5% | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. |
| CVE-2019-16955 | MEDIUM | 5.4 | 1.7% | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. |
| CVE-2019-14481 | MEDIUM | 5.4 | 0.4% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 has a Cross-Site Request Forgery (CSRF) vulnerability in the NetCrunch web client. Successfu... |
| CVE-2019-14479 | HIGH | 8.8 | 4.0% | Dec 16, 2020 | AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can exe... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now