2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3932 | CRITICAL | 9.8 | 36.3% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to authentication bypass due to a ... |
| CVE-2019-3930 | CRITICAL | 9.8 | 7.0% | Apr 30, 2019 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba... |
| CVE-2019-3929 | CRITICAL | 9.8 | 99.0% | Apr 30, 2019 | The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba... |
| CVE-2019-3927 | CRITICAL | 9.8 | 2.2% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 anyone can change the administrator and moderator... |
| CVE-2019-3926 | CRITICAL | 9.8 | 6.9% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID ... |
| CVE-2019-3925 | CRITICAL | 9.8 | 6.9% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 are vulnerable to command injection via SNMP OID ... |
| CVE-2019-10950 | CRITICAL | 9.8 | 3.6% | Apr 30, 2019 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Ca... |
| CVE-2019-3563 | CRITICAL | 9.8 | 1.7% | Apr 29, 2019 | Wangle's LineBasedFrameDecoder contains logic for identifying newlines which incorrectly advances a buffer, leading to a... |
| CVE-2019-3705 | CRITICAL | 9.8 | 4.2% | Apr 26, 2019 | Dell EMC iDRAC6 versions prior to 2.92, iDRAC7/iDRAC8 versions prior to 2.61.60.60, and iDRAC9 versions prior to 3.20.21... |
| CVE-2019-2725 | CRITICAL | 9.8 | 100.0% | Apr 26, 2019 | Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte... |
| CVE-2019-9805 | CRITICAL | 9.8 | 1.2% | Apr 26, 2019 | A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, l... |
| CVE-2019-9792 | CRITICAL | 9.8 | 13.2% | Apr 26, 2019 | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during... |
| CVE-2019-9791 | CRITICAL | 9.8 | 19.8% | Apr 26, 2019 | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w... |
| CVE-2019-9788 | CRITICAL | 9.8 | 2.2% | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunde... |
| CVE-2019-11540 | CRITICAL | 9.8 | 8.3% | Apr 26, 2019 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure versi... |
| CVE-2019-3801 | CRITICAL | 9.8 | 0.6% | Apr 25, 2019 | Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fet... |
| CVE-2019-8993 | CRITICAL | 9.8 | 2.5% | Apr 24, 2019 | The administrative web server component of TIBCO Software Inc.'s TIBCO ActiveMatrix BPM, TIBCO ActiveMatrix BPM Distribu... |
| CVE-2019-3793 | CRITICAL | 9.8 | 1.1% | Apr 24, 2019 | Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x p... |
| CVE-2019-2699 | CRITICAL | 9 | 2.9% | Apr 23, 2019 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). The supported version that is affe... |
| CVE-2019-2638 | CRITICAL | 9.9 | 1.4% | Apr 23, 2019 | Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy V... |
| CVE-2019-2633 | CRITICAL | 9.9 | 1.4% | Apr 23, 2019 | Vulnerability in the Oracle Work in Process component of Oracle E-Business Suite (subcomponent: Messages). Supported ver... |
| CVE-2019-7304 | CRITICAL | 9.8 | 61.1% | Apr 23, 2019 | Canonical snapd before version 2.37.1 incorrectly performed socket owner validation, allowing an attacker to run arbitra... |
| CVE-2019-3899 | CRITICAL | 9.8 | 1.4% | Apr 22, 2019 | It was found that default configuration of Heketi does not require any authentication potentially exposing the managemen... |
| CVE-2019-11403 | CRITICAL | 9.8 | 1.2% | Apr 22, 2019 | In Gradle Enterprise before 2018.5.2, Build Cache Nodes would reflect the configured password back when viewing the HTML... |
| CVE-2019-11402 | CRITICAL | 9.8 | 1.3% | Apr 22, 2019 | In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now