2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1663 | CRITICAL | 9.8 | 95.7% | Feb 28, 2019 | A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless... |
| CVE-2019-9215 | CRITICAL | 9.8 | 2.2% | Feb 28, 2019 | In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function. |
| CVE-2019-9201 | CRITICAL | 9.8 | 3.1% | Feb 26, 2019 | Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info... |
| CVE-2019-9195 | CRITICAL | 9.8 | 3.6% | Feb 26, 2019 | util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory t... |
| CVE-2019-9169 | CRITICAL | 9.8 | 4.7% | Feb 26, 2019 | In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer ove... |
| CVE-2019-9123 | CRITICAL | 9.8 | 1.5% | Feb 25, 2019 | An issue was discovered on D-Link DIR-825 Rev.B 2.10 devices. The "user" account has a blank password. |
| CVE-2019-8996 | CRITICAL | 9.8 | 1.6% | Feb 21, 2019 | In Signiant Manager+Agents before 13.5, the implementation of the set command has a Buffer Overflow. |
| CVE-2019-7164 | CRITICAL | 9.8 | 3.5% | Feb 20, 2019 | SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter. |
| CVE-2019-4059 | CRITICAL | 9.8 | 1.7% | Feb 15, 2019 | IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker c... |
| CVE-2019-8341 | CRITICAL | 9.8 | 44.8% | Feb 15, 2019 | An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where... |
| CVE-2019-5916 | CRITICAL | 9.8 | 1.5% | Feb 13, 2019 | Input validation issue in POWER EGG(Ver 2.0.1, Ver 2.02 Patch 3 and earlier, Ver 2.1 Patch 4 and earlier, Ver 2.2 Patch ... |
| CVE-2019-6543 | CRITICAL | 9.8 | 17.3% | Feb 13, 2019 | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)... |
| CVE-2019-6533 | CRITICAL | 9.1 | 1.2% | Feb 12, 2019 | Registers used to store Modbus values can be read and written from the web interface without authentication in the PR100... |
| CVE-2019-6527 | CRITICAL | 9.8 | 1.2% | Feb 12, 2019 | PR100088 Modbus gateway versions prior to Release R02 (or Software Version 1.1.13166) may allow an attacker to be able t... |
| CVE-2019-7653 | CRITICAL | 9.8 | 2.3% | Feb 9, 2019 | The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the curr... |
| CVE-2019-6139 | CRITICAL | 9.8 | 2.4% | Feb 7, 2019 | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. ... |
| CVE-2019-4008 | CRITICAL | 9.8 | 2.3% | Feb 7, 2019 | API Connect V2018.1 through 2018.4.1.1 is impacted by access token leak. Authorization tokens in some URLs can result in... |
| CVE-2019-3822 | CRITICAL | 9.8 | 12.8% | Feb 6, 2019 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an ... |
| CVE-2019-3464 | CRITICAL | 9.8 | 4.7% | Feb 6, 2019 | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restri... |
| CVE-2019-3463 | CRITICAL | 9.8 | 4.9% | Feb 6, 2019 | Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell t... |
| CVE-2019-1000006 | CRITICAL | 9.8 | 1.6% | Feb 4, 2019 | RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in s... |
| CVE-2019-1651 | CRITICAL | 9.9 | 4.9% | Jan 24, 2019 | A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a ... |
| CVE-2019-3773 | CRITICAL | 9.8 | 4.1% | Jan 18, 2019 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XM... |
| CVE-2019-0022 | CRITICAL | 10 | 1.1% | Jan 15, 2019 | Juniper ATP ships with hard coded credentials in the Cyphort Core instance which gives an attacker the ability to take f... |
| CVE-2019-0020 | CRITICAL | 10 | 1.6% | Jan 15, 2019 | Juniper ATP ships with hard coded credentials in the Web Collector instance which gives an attacker the ability to take ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now