2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11853 | HIGH | 7.2 | 1.2% | Aug 21, 2020 | Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4... |
| CVE-2019-11852 | CRITICAL | 9.1 | 0.9% | Aug 21, 2020 | An out-of-bounds reads vulnerability exists in the ACEView Service of ALEOS before 4.13.0, 4.9.5, and 4.4.9. Sensitive i... |
| CVE-2019-11850 | MEDIUM | 6.7 | 0.4% | Aug 21, 2020 | A stack overflow vulnerabiltity exist in the AT command interface of ALEOS before 4.11.0. The vulnerability may allow co... |
| CVE-2019-11849 | MEDIUM | 6.7 | 0.4% | Aug 21, 2020 | A stack overflow vulnerabiltity exists in the AT command APIs of ALEOS before 4.11.0. The vulnerability may allow code e... |
| CVE-2019-11848 | HIGH | 7.2 | 1.1% | Aug 21, 2020 | An API abuse vulnerability exists in the AT command API of ALEOS before 4.13.0, 4.9.5, 4.4.9 due to lack of length check... |
| CVE-2019-11847 | HIGH | 7.8 | 0.4% | Aug 21, 2020 | An improper privilege management vulnerabitlity exists in ALEOS before 4.11.0, 4.9.4 and 4.4.9. An authenticated user ca... |
| CVE-2019-19184 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19183 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19181 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19179 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19178 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19173 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19123 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19121 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19120 | — | — | — | Aug 21, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-20152 | MEDIUM | 6.1 | 0.7% | Aug 20, 2020 | An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, mal... |
| CVE-2019-20151 | MEDIUM | 6.1 | 0.7% | Aug 20, 2020 | An XSS issue was discovered in TreasuryXpress 19191105. Due to the lack of filtering and sanitization of user input, mal... |
| CVE-2019-20150 | MEDIUM | 6.5 | 0.9% | Aug 20, 2020 | In TreasuryXpress 19191105, a logged-in user can discover saved credentials, even though the UI hides them. Using functi... |
| CVE-2019-6258 | CRITICAL | 9.8 | 2.6% | Aug 18, 2020 | D-Link DIR-822 Rev.Bx devices with firmware v.202KRb06 and older allow a buffer overflow via long MacAddress data in a /... |
| CVE-2019-5591 | MEDIUM | 6.5 | 18.6% | Aug 14, 2020 | A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept s... |
| CVE-2019-19643 | HIGH | 7.5 | 1.4% | Aug 14, 2020 | ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service. |
| CVE-2019-7410 | MEDIUM | 6.1 | 1.2% | Aug 14, 2020 | There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web ... |
| CVE-2019-6112 | MEDIUM | 6.1 | 8.9% | Aug 14, 2020 | A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows... |
| CVE-2019-20383 | HIGH | 7.8 | 0.5% | Aug 13, 2020 | ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges... |
| CVE-2019-16374 | CRITICAL | 9.8 | 1.9% | Aug 13, 2020 | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. A... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now