2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10773 | HIGH | 7.8 | 1.5% | Dec 16, 2019 | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesy... |
| CVE-2019-0159 | HIGH | 7.8 | 0.4% | Dec 16, 2019 | Insufficient memory protection in the Linux Administrative Tools for Intel(R) Network Adapters before version 24.3 may a... |
| CVE-2019-0134 | HIGH | 7.8 | 0.4% | Dec 16, 2019 | Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an auth... |
| CVE-2019-19731 | HIGH | 7.5 | 11.6% | Dec 16, 2019 | Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary loc... |
| CVE-2019-19331 | HIGH | 7.5 | 2.2% | Dec 16, 2019 | knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with ver... |
| CVE-2019-19807 | HIGH | 7.8 | 0.6% | Dec 15, 2019 | In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID... |
| CVE-2019-5277 | HIGH | 7.5 | 0.8% | Dec 13, 2019 | Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the a... |
| CVE-2019-5254 | HIGH | 8.6 | 0.7% | Dec 13, 2019 | Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;... |
| CVE-2019-19796 | HIGH | 7.8 | 0.8% | Dec 13, 2019 | Yabasic 2.86.2 has a heap-based buffer overflow in myformat in function.c via a crafted BASIC source file. |
| CVE-2019-19795 | HIGH | 7.8 | 0.8% | Dec 13, 2019 | samurai 0.7 has a heap-based buffer overflow in canonpath in util.c via a crafted build file. |
| CVE-2019-16732 | HIGH | 8.1 | 0.9% | Dec 13, 2019 | Unencrypted HTTP communications for firmware upgrades in Petalk AI and PF-103 allow man-in-the-middle attackers to run a... |
| CVE-2019-16731 | HIGH | 7.5 | 1.1% | Dec 13, 2019 | The udpServerSys service in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to initiate... |
| CVE-2019-19793 | HIGH | 8.8 | 1.0% | Dec 13, 2019 | In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain c... |
| CVE-2019-19774 | HIGH | 8.8 | 12.5% | Dec 13, 2019 | An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai... |
| CVE-2019-17123 | HIGH | 7.5 | 1.0% | Dec 13, 2019 | The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email)... |
| CVE-2019-19787 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 fi... |
| CVE-2019-19786 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file. |
| CVE-2019-19785 | HIGH | 7.8 | 1.2% | Dec 13, 2019 | ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file. |
| CVE-2019-5250 | HIGH | 7.8 | 0.6% | Dec 13, 2019 | Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. ... |
| CVE-2019-5248 | HIGH | 7.4 | 0.3% | Dec 13, 2019 | CloudEngine 12800 has a DoS vulnerability. An attacker of a neighboring device sends a large number of specific packets.... |
| CVE-2019-19397 | HIGH | 7.5 | 0.8% | Dec 13, 2019 | There is a weak algorithm vulnerability in some Huawei products. The affected products use weak algorithms by default. A... |
| CVE-2019-19501 | HIGH | 7.8 | 0.5% | Dec 13, 2019 | VeraCrypt 1.24 allows Local Privilege Escalation during execution of VeraCryptExpander.exe. |
| CVE-2019-18838 | HIGH | 7.5 | 2.1% | Dec 13, 2019 | An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an int... |
| CVE-2019-13347 | HIGH | 7.5 | 1.1% | Dec 13, 2019 | An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 ... |
| CVE-2019-19778 | HIGH | 8.8 | 1.4% | Dec 13, 2019 | An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now