2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8455 | HIGH | 7.1 | 0.4% | Apr 17, 2019 | A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its per... |
| CVE-2019-8453 | — | — | 0.3% | Apr 17, 2019 | Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write pe... |
| CVE-2019-10953 | HIGH | 7.5 | 3.7% | Apr 17, 2019 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers... |
| CVE-2019-10951 | HIGH | 7.8 | 2.9% | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow... |
| CVE-2019-10949 | — | — | 2.4% | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple out-of-bounds read vulnera... |
| CVE-2019-10947 | HIGH | 7.8 | 3.7% | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflo... |
| CVE-2019-0228 | CRITICAL | 9.8 | 9.5% | Apr 17, 2019 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XM... |
| CVE-2019-6153 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6151 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6152 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6150 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9499 | HIGH | 8.1 | 2.4% | Apr 17, 2019 | The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validati... |
| CVE-2019-9498 | HIGH | 8.1 | 2.4% | Apr 17, 2019 | The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on... |
| CVE-2019-9497 | — | — | 5.4% | Apr 17, 2019 | The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element ... |
| CVE-2019-9496 | — | — | 5.2% | Apr 17, 2019 | An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps... |
| CVE-2019-9495 | LOW | 3.7 | 3.4% | Apr 17, 2019 | The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache... |
| CVE-2019-9494 | MEDIUM | 5.9 | 3.7% | Apr 17, 2019 | The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observabl... |
| CVE-2019-6579 | CRITICAL | 9.8 | 2.3% | Apr 17, 2019 | A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the... |
| CVE-2019-6575 | HIGH | 7.5 | 1.6% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515... |
| CVE-2019-6570 | HIGH | 8.8 | 1.4% | Apr 17, 2019 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to insufficient checking ... |
| CVE-2019-6568 | HIGH | 7.5 | 1.4% | Apr 17, 2019 | The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attac... |
| CVE-2019-3883 | HIGH | 7.5 | 8.4% | Apr 17, 2019 | In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker... |
| CVE-2019-3798 | MEDIUM | 6 | 1.4% | Apr 17, 2019 | Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating u... |
| CVE-2019-3709 | HIGH | 8.3 | 2.2% | Apr 17, 2019 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while registering vCenter servers. A remo... |
| CVE-2019-3708 | HIGH | 8.3 | 2.2% | Apr 17, 2019 | IsilonSD Management Server 1.1.0 contains a cross-site scripting vulnerability while uploading an OVA file. A remote att... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now