2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0039 | HIGH | 8.1 | 1.3% | Apr 10, 2019 | If REST API is enabled, the Junos OS login credentials are vulnerable to brute force attacks. The high default connectio... |
| CVE-2019-0038 | MEDIUM | 6.5 | 0.7% | Apr 10, 2019 | Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial ... |
| CVE-2019-0037 | HIGH | 7.5 | 1.3% | Apr 10, 2019 | In a Dynamic Host Configuration Protocol version 6 (DHCPv6) environment, the jdhcpd daemon may crash and restart upon re... |
| CVE-2019-0036 | CRITICAL | 9.8 | 1.0% | Apr 10, 2019 | When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", ... |
| CVE-2019-0035 | MEDIUM | 6.8 | 0.4% | Apr 10, 2019 | When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the roo... |
| CVE-2019-0034 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was withdrawn by its CNA. Further investigatio... |
| CVE-2019-0033 | HIGH | 7.5 | 1.6% | Apr 10, 2019 | A firewall bypass vulnerability in the proxy ARP service of Juniper Networks Junos OS allows an attacker to cause a high... |
| CVE-2019-0032 | HIGH | 7.8 | 0.4% | Apr 10, 2019 | A password management issue exists where the Organization authentication username and password were stored in plaintext ... |
| CVE-2019-0031 | HIGH | 7.5 | 1.7% | Apr 10, 2019 | Specific IPv6 DHCP packets received by the jdhcpd daemon will cause a memory resource consumption issue to occur on a Ju... |
| CVE-2019-0028 | HIGH | 7.5 | 1.2% | Apr 10, 2019 | On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP ... |
| CVE-2019-0019 | HIGH | 7.5 | 1.1% | Apr 10, 2019 | When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to cras... |
| CVE-2019-0008 | CRITICAL | 9.8 | 4.5% | Apr 10, 2019 | A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet For... |
| CVE-2019-10946 | — | — | 1.1% | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access chec... |
| CVE-2019-10945 | — | — | 38.0% | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param... |
| CVE-2019-0208 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7139 | — | — | 17.4% | Apr 10, 2019 | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca... |
| CVE-2019-5426 | MEDIUM | 4.8 | 0.8% | Apr 10, 2019 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dyn... |
| CVE-2019-5425 | — | — | 1.9% | Apr 10, 2019 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the ... |
| CVE-2019-5424 | HIGH | 8.8 | 1.9% | Apr 10, 2019 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, a privileged user can execute arbitrary shell commands over the SSH ... |
| CVE-2019-7551 | CRITICAL | 9 | 1.8% | Apr 10, 2019 | Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would en... |
| CVE-2019-6156 | — | — | 0.2% | Apr 10, 2019 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot... |
| CVE-2019-6154 | MEDIUM | 5.3 | 0.9% | Apr 10, 2019 | A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a... |
| CVE-2019-6287 | — | — | 1.0% | Apr 10, 2019 | In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in ... |
| CVE-2019-4013 | CRITICAL | 9 | 14.1% | Apr 10, 2019 | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr... |
| CVE-2019-0199 | — | — | 72.9% | Apr 10, 2019 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive number... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now