2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20925 | HIGH | 7.5 | 1.7% | Nov 24, 2020 | An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause... |
| CVE-2019-14587 | MEDIUM | 6.5 | 0.6% | Nov 23, 2020 | Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access. |
| CVE-2019-14586 | HIGH | 8 | 0.7% | Nov 23, 2020 | Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, in... |
| CVE-2019-14575 | HIGH | 7.8 | 0.4% | Nov 23, 2020 | Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation... |
| CVE-2019-14563 | HIGH | 7.8 | 0.4% | Nov 23, 2020 | Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local acc... |
| CVE-2019-2393 | MEDIUM | 6.5 | 1.2% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-2392 | MEDIUM | 6.5 | 1.2% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-20924 | MEDIUM | 6.5 | 1.3% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which t... |
| CVE-2019-20923 | MEDIUM | 6.5 | 1.3% | Nov 23, 2020 | A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ... |
| CVE-2019-14562 | MEDIUM | 5.5 | 0.3% | Nov 23, 2020 | Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of... |
| CVE-2019-14559 | HIGH | 7.5 | 1.3% | Nov 23, 2020 | Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service vi... |
| CVE-2019-14553 | MEDIUM | 4.9 | 1.4% | Nov 23, 2020 | Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network a... |
| CVE-2019-20933 | CRITICAL | 9.8 | 30.9% | Nov 19, 2020 | InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.... |
| CVE-2019-12412 | HIGH | 7.5 | 3.9% | Nov 19, 2020 | A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remot... |
| CVE-2019-19563 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to ... |
| CVE-2019-19562 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to d... |
| CVE-2019-19561 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to ... |
| CVE-2019-19560 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to d... |
| CVE-2019-19557 | LOW | 2.4 | 0.4% | Nov 16, 2020 | A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to de... |
| CVE-2019-19556 | MEDIUM | 4.6 | 0.5% | Nov 16, 2020 | An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to dev... |
| CVE-2019-17566 | HIGH | 7.5 | 10.7% | Nov 12, 2020 | Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attri... |
| CVE-2019-11121 | HIGH | 7.8 | 0.3% | Nov 12, 2020 | Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an au... |
| CVE-2019-7357 | HIGH | 8.8 | 1.4% | Nov 10, 2020 | Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins. |
| CVE-2019-7356 | MEDIUM | 5.4 | 0.7% | Nov 4, 2020 | Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter. |
| CVE-2019-4349 | LOW | 3.5 | 0.3% | Nov 3, 2020 | IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating syste... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now