2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1655 | MEDIUM | 6.1 | 0.9% | Jan 24, 2019 | A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, rem... |
| CVE-2019-1653 | HIGH | 7.5 | 99.9% | Jan 24, 2019 | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route... |
| CVE-2019-6777 | — | — | 1.0% | Jan 24, 2019 | An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/ind... |
| CVE-2019-1652 | HIGH | 7.2 | 95.9% | Jan 24, 2019 | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Route... |
| CVE-2019-1651 | CRITICAL | 9.9 | 4.9% | Jan 24, 2019 | A vulnerability in the vContainer of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to cause a ... |
| CVE-2019-1650 | HIGH | 8.8 | 3.5% | Jan 24, 2019 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files ... |
| CVE-2019-1648 | HIGH | 7.8 | 0.4% | Jan 24, 2019 | A vulnerability in the user group configuration of the Cisco SD-WAN Solution could allow an authenticated, local attacke... |
| CVE-2019-1647 | HIGH | 8 | 0.8% | Jan 24, 2019 | A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication an... |
| CVE-2019-1646 | HIGH | 7.8 | 0.4% | Jan 24, 2019 | A vulnerability in the local CLI of the Cisco SD-WAN Solution could allow an authenticated, local attacker to escalate p... |
| CVE-2019-1645 | MEDIUM | 4.3 | 0.5% | Jan 24, 2019 | A vulnerability in the Cisco Connected Mobile Experiences (CMX) software could allow an unauthenticated, adjacent attack... |
| CVE-2019-6486 | — | — | 4.3% | Jan 24, 2019 | Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a ... |
| CVE-2019-1644 | HIGH | 7.5 | 2.3% | Jan 23, 2019 | A vulnerability in the UDP protocol implementation for Cisco IoT Field Network Director (IoT-FND) could allow an unauthe... |
| CVE-2019-1643 | MEDIUM | 6.1 | 1.2% | Jan 23, 2019 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an unauthenticated, remo... |
| CVE-2019-1642 | MEDIUM | 6.1 | 3.9% | Jan 23, 2019 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) software could allow an... |
| CVE-2019-1641 | HIGH | 7.8 | 1.4% | Jan 23, 2019 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso... |
| CVE-2019-1640 | HIGH | 7.8 | 1.5% | Jan 23, 2019 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso... |
| CVE-2019-1639 | HIGH | 7.8 | 1.5% | Jan 23, 2019 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso... |
| CVE-2019-1638 | HIGH | 7.8 | 1.5% | Jan 23, 2019 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso... |
| CVE-2019-1637 | HIGH | 7.8 | 1.5% | Jan 23, 2019 | A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microso... |
| CVE-2019-6719 | — | — | 1.5% | Jan 23, 2019 | An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_... |
| CVE-2019-1636 | HIGH | 7.8 | 46.9% | Jan 23, 2019 | A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary comm... |
| CVE-2019-6713 | — | — | 2.4% | Jan 23, 2019 | app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by... |
| CVE-2019-6708 | — | — | 1.0% | Jan 23, 2019 | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. |
| CVE-2019-6707 | — | — | 1.0% | Jan 23, 2019 | PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter. |
| CVE-2019-6706 | HIGH | 7.5 | 17.2% | Jan 23, 2019 | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now