2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8352 | CRITICAL | 9.8 | 6.3% | May 20, 2019 | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen... |
| CVE-2019-4279 | CRITICAL | 9.8 | 80.4% | May 17, 2019 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with ... |
| CVE-2019-10910 | CRITICAL | 9.8 | 5.5% | May 16, 2019 | In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when servic... |
| CVE-2019-0708 | CRITICAL | 9.8 | 100.0% | May 16, 2019 | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau... |
| CVE-2019-3725 | CRITICAL | 9.8 | 2.8% | May 15, 2019 | RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable ... |
| CVE-2019-6572 | CRITICAL | 9.1 | 2.7% | May 14, 2019 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI ... |
| CVE-2019-3568 | CRITICAL | 9.8 | 39.2% | May 14, 2019 | A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of RTC... |
| CVE-2019-10922 | CRITICAL | 9.8 | 2.6% | May 14, 2019 | A vulnerability has been identified in SIMATIC PCS 7 V8.0 and earlier (All versions), SIMATIC PCS 7 V8.1 and newer (All ... |
| CVE-2019-10919 | CRITICAL | 9.4 | 2.7% | May 14, 2019 | A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Attackers with access t... |
| CVE-2019-1867 | CRITICAL | 10 | 30.3% | May 10, 2019 | A vulnerability in the REST API of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attack... |
| CVE-2019-6548 | CRITICAL | 9.8 | 1.3% | May 9, 2019 | GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may all... |
| CVE-2019-11835 | CRITICAL | 9.8 | 2.6% | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. |
| CVE-2019-11834 | CRITICAL | 9.8 | 2.5% | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. |
| CVE-2019-11831 | CRITICAL | 9.8 | 5.6% | May 9, 2019 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent... |
| CVE-2019-5021 | CRITICAL | 9.8 | 6.3% | May 8, 2019 | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne... |
| CVE-2019-11510 | CRITICAL | 10 | 100.0% | May 8, 2019 | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent... |
| CVE-2019-9505 | CRITICAL | 9.8 | 3.5% | May 8, 2019 | The PrinterLogic Print Management software, versions up to and including 18.3.1.96, does not sanitize special characters... |
| CVE-2019-11766 | CRITICAL | 9.8 | 2.1% | May 5, 2019 | dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. |
| CVE-2019-11036 | CRITICAL | 9.1 | 6.8% | May 3, 2019 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3... |
| CVE-2019-1804 | CRITICAL | 9.8 | 3.4% | May 3, 2019 | A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode ... |
| CVE-2019-11683 | CRITICAL | 9.8 | 7.1% | May 2, 2019 | udp_gro_receive_segment in net/ipv4/udp_offload.c in the Linux kernel 5.x before 5.0.13 allows remote attackers to cause... |
| CVE-2019-10952 | CRITICAL | 9.8 | 10.0% | May 1, 2019 | An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code exec... |
| CVE-2019-11627 | CRITICAL | 9.8 | 2.8% | Apr 30, 2019 | gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a Use... |
| CVE-2019-3939 | CRITICAL | 9.8 | 2.8% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator... |
| CVE-2019-3935 | CRITICAL | 9.1 | 3.3% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 allows anyone to act as a moderator to a slide sh... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now