2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6525 | HIGH | 8.8 | 1.4% | Apr 11, 2019 | AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of sy... |
| CVE-2019-9628 | HIGH | 7.5 | 2.1% | Apr 11, 2019 | The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software... |
| CVE-2019-9056 | — | — | 1.3% | Apr 11, 2019 | An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate... |
| CVE-2019-7644 | — | — | 1.7% | Apr 11, 2019 | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfull... |
| CVE-2019-6796 | — | — | 1.2% | Apr 11, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-6493 | — | — | 0.5% | Apr 11, 2019 | SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user de... |
| CVE-2019-9976 | — | — | 1.0% | Apr 11, 2019 | The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, w... |
| CVE-2019-9975 | — | — | 1.3% | Apr 11, 2019 | DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be... |
| CVE-2019-9974 | — | — | 2.9% | Apr 11, 2019 | diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote at... |
| CVE-2019-9733 | — | — | 53.9% | Apr 11, 2019 | An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password o... |
| CVE-2019-7219 | — | — | 5.2% | Apr 11, 2019 | Unauthenticated reflected cross-site scripting (XSS) exists in Zarafa Webapp 2.0.1.47791 and earlier. NOTE: this is a di... |
| CVE-2019-5715 | — | — | 1.6% | Apr 11, 2019 | All versions of SilverStripe 3 prior to 3.6.7 and 3.7.3, and all versions of SilverStripe 4 prior to 4.0.7, 4.1.5, 4.2.4... |
| CVE-2019-6610 | — | — | 1.1% | Apr 11, 2019 | On BIG-IP versions 14.0.0-14.0.0.4, 13.0.0-13.1.1.1, 12.1.0-12.1.4, 11.6.0-11.6.3.4, and 11.5.1-11.5.8, the system is vu... |
| CVE-2019-5024 | HIGH | 7.6 | 0.5% | Apr 11, 2019 | A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neur... |
| CVE-2019-5673 | — | — | 0.3% | Apr 11, 2019 | NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Me... |
| CVE-2019-5672 | — | — | 1.4% | Apr 11, 2019 | NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior t... |
| CVE-2019-3460 | MEDIUM | 6.5 | 1.8% | Apr 11, 2019 | A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1. |
| CVE-2019-3459 | MEDIUM | 6.5 | 1.8% | Apr 11, 2019 | A heap address information leak while using L2CAP_GET_CONF_OPT was discovered in the Linux kernel before 5.1-rc1. |
| CVE-2019-6318 | — | — | 2.6% | Apr 11, 2019 | HP LaserJet Enterprise printers, HP PageWide Enterprise printers, HP LaserJet Managed printers, HP Officejet Enterprise ... |
| CVE-2019-3916 | — | — | 2.1% | Apr 11, 2019 | Information disclosure vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows an remo... |
| CVE-2019-3845 | HIGH | 8 | 0.7% | Apr 11, 2019 | A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent... |
| CVE-2019-3837 | MEDIUM | 6.1 | 0.2% | Apr 11, 2019 | It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unp... |
| CVE-2019-3915 | — | — | 0.6% | Apr 11, 2019 | Authentication Bypass by Capture-replay vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.... |
| CVE-2019-3914 | — | — | 29.9% | Apr 11, 2019 | Remote command injection vulnerability in Verizon Fios Quantum Gateway (G1100) firmware version 02.01.00.05 allows a rem... |
| CVE-2019-11078 | — | — | 0.6% | Apr 11, 2019 | MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now