2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6030 | HIGH | 8.8 | 0.7% | Dec 26, 2019 | Cross-site request forgery (CSRF) vulnerability in Custom Body Class 0.6.0 and earlier allows remote attackers to hijack... |
| CVE-2019-6027 | HIGH | 8.8 | 0.7% | Dec 26, 2019 | Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack th... |
| CVE-2019-6026 | HIGH | 7.8 | 0.4% | Dec 26, 2019 | Privilege escalation vulnerability in Multiple MOTEX products (LanScope Cat client program (MR) and LanScope Cat client ... |
| CVE-2019-6019 | HIGH | 7.8 | 0.8% | Dec 26, 2019 | Untrusted search path vulnerability in STAMP Workbench installer all versions allows an attacker to gain privileges via ... |
| CVE-2019-6014 | HIGH | 8.8 | 1.2% | Dec 26, 2019 | DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface. |
| CVE-2019-6012 | HIGH | 7.2 | 1.4% | Dec 26, 2019 | SQL injection vulnerability in the wpDataTables Lite Version 2.0.11 and earlier allows remote authenticated attackers to... |
| CVE-2019-6008 | HIGH | 7.8 | 1.3% | Dec 26, 2019 | An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (... |
| CVE-2019-19681 | HIGH | 8.8 | 4.6% | Dec 26, 2019 | Pandora FMS 7.x suffers from remote code execution vulnerability. With an authenticated user who can modify the alert sy... |
| CVE-2019-15695 | HIGH | 7.2 | 4.5% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to stack buffer overflow, which could be triggered from CMsgReader::readS... |
| CVE-2019-15694 | HIGH | 7.2 | 4.5% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which could be triggered from DecodeManager::dec... |
| CVE-2019-15693 | HIGH | 7.2 | 4.3% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow, which occurs in TightDecoder::FilterGradient. Ex... |
| CVE-2019-15692 | HIGH | 7.2 | 4.8% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to heap buffer overflow. Vulnerability could be triggered from CopyRectDe... |
| CVE-2019-15691 | HIGH | 7.2 | 4.7% | Dec 26, 2019 | TigerVNC version prior to 1.10.1 is vulnerable to stack use-after-return, which occurs due to incorrect usage of stack m... |
| CVE-2019-19999 | HIGH | 7.2 | 1.5% | Dec 26, 2019 | Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is no... |
| CVE-2019-19998 | HIGH | 7.5 | 1.1% | Dec 26, 2019 | Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php. |
| CVE-2019-19979 | HIGH | 8.8 | 0.6% | Dec 26, 2019 | A flaw in the WordPress plugin, WP Maintenance before 5.0.6, allowed attackers to enable a vulnerable site's maintenance... |
| CVE-2019-19967 | HIGH | 7.5 | 1.0% | Dec 25, 2019 | The Administration page on Connect Box EuroDOCSIS 3.0 Voice Gateway CH7465LG-NCIP-6.12.18.25-2p6-NOSH devices accepts a ... |
| CVE-2019-19962 | HIGH | 7.5 | 0.9% | Dec 25, 2019 | wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography. |
| CVE-2019-5702 | HIGH | 7.8 | 0.4% | Dec 24, 2019 | NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an... |
| CVE-2019-19925 | HIGH | 7.5 | 6.8% | Dec 24, 2019 | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. |
| CVE-2019-19956 | HIGH | 7.5 | 5.5% | Dec 24, 2019 | xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
| CVE-2019-19923 | HIGH | 7.5 | 6.8% | Dec 24, 2019 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which t... |
| CVE-2019-19954 | HIGH | 7.3 | 0.5% | Dec 24, 2019 | Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\n... |
| CVE-2019-19695 | HIGH | 7.5 | 3.2% | Dec 24, 2019 | A privilege escalation vulnerability in Trend Micro Antivirus for Mac 2019 (v9.0.1379 and below) could potentially allow... |
| CVE-2019-18211 | HIGH | 8.8 | 2.9% | Dec 23, 2019 | An issue was discovered in Orckestra C1 CMS through 6.6. The EntityTokenSerializer class in Composite.dll is prone to un... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now