2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14557 | HIGH | 8 | 0.5% | Oct 5, 2020 | Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5... |
| CVE-2019-14556 | MEDIUM | 4.4 | 0.3% | Oct 5, 2020 | Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor ... |
| CVE-2019-19199 | HIGH | 7.4 | 1.1% | Oct 2, 2020 | REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout... |
| CVE-2019-19393 | MEDIUM | 6.1 | 0.8% | Oct 1, 2020 | The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on... |
| CVE-2019-20903 | MEDIUM | 5.4 | 1.1% | Oct 1, 2020 | The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitra... |
| CVE-2019-20902 | HIGH | 7.5 | 0.9% | Oct 1, 2020 | Upgrading Crowd via XML Data Transfer can reactivate a disabled user from OpenLDAP. The affected versions are from befor... |
| CVE-2019-20922 | HIGH | 7.5 | 3.8% | Sep 30, 2020 | Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be... |
| CVE-2019-20921 | MEDIUM | 6.1 | 1.7% | Sep 30, 2020 | bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. Th... |
| CVE-2019-20920 | HIGH | 8.1 | 3.2% | Sep 30, 2020 | Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to prope... |
| CVE-2019-18991 | MEDIUM | 5.4 | 0.5% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d... |
| CVE-2019-18990 | MEDIUM | 5.4 | 0.8% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RT... |
| CVE-2019-18989 | MEDIUM | 5.4 | 0.8% | Sep 30, 2020 | A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending ... |
| CVE-2019-17098 | MEDIUM | 6.5 | 0.5% | Sep 30, 2020 | Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacke... |
| CVE-2019-16212 | HIGH | 8.8 | 1.3% | Sep 25, 2020 | A vulnerability in Brocade SANnav versions before v2.1.0 could allow a remote authenticated attacker to conduct an LDAP ... |
| CVE-2019-16211 | CRITICAL | 9.8 | 1.0% | Sep 25, 2020 | Brocade SANnav versions before v2.1.0, contain a Plaintext Password Storage vulnerability. |
| CVE-2019-11556 | MEDIUM | 6.1 | 1.0% | Sep 25, 2020 | Pagure before 5.6 allows XSS via the templates/blame.html blame view. |
| CVE-2019-7178 | HIGH | 7.2 | 1.5% | Sep 25, 2020 | Pexip Infinity before 20.1 allows privilege escalation by restoring a system backup. |
| CVE-2019-7177 | HIGH | 7.2 | 1.4% | Sep 25, 2020 | Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin. |
| CVE-2019-1983 | MEDIUM | 5.3 | 1.9% | Sep 23, 2020 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA... |
| CVE-2019-1947 | HIGH | 8.6 | 1.9% | Sep 23, 2020 | A vulnerability in the email message filtering feature of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA... |
| CVE-2019-1888 | HIGH | 7.2 | 3.4% | Sep 23, 2020 | A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an... |
| CVE-2019-1736 | MEDIUM | 6.6 | 0.2% | Sep 23, 2020 | A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an authenticated, physical attacker t... |
| CVE-2019-16028 | CRITICAL | 9.8 | 3.4% | Sep 23, 2020 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthen... |
| CVE-2019-16025 | MEDIUM | 4.8 | 0.6% | Sep 23, 2020 | A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to condu... |
| CVE-2019-16023 | HIGH | 7.5 | 1.3% | Sep 23, 2020 | Multiple vulnerabilities in the implementation of Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cis... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now