2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19875 | CRITICAL | 9.8 | 1.5% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Arbitrary commands could be injected (usin... |
| CVE-2019-19874 | CRITICAL | 9.8 | 1.8% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. Some web scripts in the web interface allo... |
| CVE-2019-19873 | HIGH | 7.5 | 1.2% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the A... |
| CVE-2019-19872 | CRITICAL | 9.8 | 1.2% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. The AprolLoader could be used to inject an... |
| CVE-2019-19869 | HIGH | 7.5 | 0.9% | Nov 27, 2020 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by usin... |
| CVE-2019-20925 | HIGH | 7.5 | 1.7% | Nov 24, 2020 | An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause... |
| CVE-2019-14587 | MEDIUM | 6.5 | 0.6% | Nov 23, 2020 | Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
| CVE-2019-14586 | HIGH | 8 | 0.7% | Nov 23, 2020 | Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, in... |
| CVE-2019-14575 | HIGH | 7.8 | 0.4% | Nov 23, 2020 | Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation... |
| CVE-2019-14563 | HIGH | 7.8 | 0.4% | Nov 23, 2020 | Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local acc... |
| CVE-2019-2393 | MEDIUM | 6.5 | 1.2% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-2392 | MEDIUM | 6.5 | 1.2% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-20924 | MEDIUM | 6.5 | 1.3% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which t... |
| CVE-2019-20923 | MEDIUM | 6.5 | 1.3% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-14562 | MEDIUM | 5.5 | 0.3% | Nov 23, 2020 | Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of... |
| CVE-2019-14559 | HIGH | 7.5 | 1.3% | Nov 23, 2020 | Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service vi... |
| CVE-2019-14553 | MEDIUM | 4.9 | 1.4% | Nov 23, 2020 | Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network a... |
| CVE-2019-20933 | CRITICAL | 9.8 | 30.9% | Nov 19, 2020 | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.... |
| CVE-2019-12412 | HIGH | 7.5 | 3.9% | Nov 19, 2020 | A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remot... |
| CVE-2019-19563 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to ... |
| CVE-2019-19562 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to d... |
| CVE-2019-19561 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to ... |
| CVE-2019-19560 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to d... |
| CVE-2019-19557 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to de... |
| CVE-2019-19556 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to dev... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now