2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9213 | MEDIUM | 5.5 | 5.7% | Mar 5, 2019 | In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make... |
| CVE-2019-9576 | — | — | 1.4% | Mar 5, 2019 | The Blog2Social plugin before 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS. |
| CVE-2019-9575 | — | — | 1.6% | Mar 5, 2019 | The Quiz And Survey Master plugin 6.0.4 for WordPress allows wp-admin/admin.php?page=mlw_quiz_results quiz_id XSS. |
| CVE-2019-9574 | — | — | 2.4% | Mar 5, 2019 | The WP Human Resource Management plugin before 2.2.6 for WordPress does not ensure that a leave modification occurs in t... |
| CVE-2019-9573 | — | — | 1.8% | Mar 5, 2019 | The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications. |
| CVE-2019-3922 | CRITICAL | 9.8 | 5.2% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via ... |
| CVE-2019-3921 | HIGH | 8.8 | 18.2% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via ... |
| CVE-2019-3920 | HIGH | 8.8 | 3.9% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command inject... |
| CVE-2019-3919 | HIGH | 8.8 | 3.9% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafte... |
| CVE-2019-3918 | CRITICAL | 9.8 | 2.0% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for ... |
| CVE-2019-3917 | HIGH | 7.5 | 2.4% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to ... |
| CVE-2019-6565 | MEDIUM | 6.1 | 1.1% | Mar 5, 2019 | Moxa IKS and EDS fails to properly validate user input, giving unauthenticated and authenticated attackers the ability t... |
| CVE-2019-6563 | CRITICAL | 9.8 | 1.7% | Mar 5, 2019 | Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administ... |
| CVE-2019-6561 | HIGH | 8.8 | 1.2% | Mar 5, 2019 | Cross-site request forgery has been identified in Moxa IKS and EDS, which may allow for the execution of unauthorized ac... |
| CVE-2019-6559 | MEDIUM | 6.5 | 2.4% | Mar 5, 2019 | Moxa IKS and EDS allow remote authenticated users to cause a denial of service via a specially crafted packet, which may... |
| CVE-2019-6557 | CRITICAL | 9.8 | 5.0% | Mar 5, 2019 | Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution. |
| CVE-2019-6528 | HIGH | 8.8 | 2.6% | Mar 5, 2019 | PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol G... |
| CVE-2019-6524 | CRITICAL | 9.8 | 2.7% | Mar 5, 2019 | Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allo... |
| CVE-2019-6522 | CRITICAL | 9.1 | 2.5% | Mar 5, 2019 | Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary add... |
| CVE-2019-6520 | HIGH | 7.5 | 1.7% | Mar 5, 2019 | Moxa IKS and EDS does not properly check authority on server side, which results in a read-only user being able to perfo... |
| CVE-2019-6518 | HIGH | 7.5 | 1.2% | Mar 5, 2019 | Moxa IKS and EDS store plaintext passwords, which may allow sensitive information to be read by someone with access to t... |
| CVE-2019-4063 | MEDIUM | 5.9 | 1.0% | Mar 5, 2019 | IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 Standard Edition could allow highly sensitive information to be tran... |
| CVE-2019-4032 | CRITICAL | 9.8 | 1.6% | Mar 5, 2019 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote... |
| CVE-2019-4029 | MEDIUM | 5.4 | 1.0% | Mar 5, 2019 | IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows use... |
| CVE-2019-4028 | MEDIUM | 5.4 | 1.0% | Mar 5, 2019 | IBM Sterling B2B Integrator 5.2.0.1 through 6.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows use... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now