2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19643 | HIGH | 7.5 | 1.4% | Aug 14, 2020 | ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service. |
| CVE-2019-7410 | MEDIUM | 6.1 | 1.2% | Aug 14, 2020 | There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web ... |
| CVE-2019-6112 | MEDIUM | 6.1 | 8.9% | Aug 14, 2020 | A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows... |
| CVE-2019-20383 | HIGH | 7.8 | 0.5% | Aug 13, 2020 | ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges... |
| CVE-2019-16374 | CRITICAL | 9.8 | 1.9% | Aug 13, 2020 | Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. A... |
| CVE-2019-4582 | MEDIUM | 4.3 | 1.4% | Aug 13, 2020 | IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An atta... |
| CVE-2019-14620 | MEDIUM | 6.5 | 0.5% | Aug 13, 2020 | Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to ... |
| CVE-2019-14630 | MEDIUM | 4.6 | 0.3% | Aug 13, 2020 | Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticat... |
| CVE-2019-17339 | HIGH | 8.1 | 0.8% | Aug 11, 2020 | The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically all... |
| CVE-2019-19704 | HIGH | 7.5 | 1.3% | Aug 8, 2020 | In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm. |
| CVE-2019-7005 | HIGH | 7.5 | 1.2% | Aug 7, 2020 | A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthen... |
| CVE-2019-20001 | HIGH | 7.8 | 0.3% | Aug 4, 2020 | An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to es... |
| CVE-2019-19455 | HIGH | 7.8 | 0.4% | Aug 3, 2020 | Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in ... |
| CVE-2019-19453 | MEDIUM | 5.4 | 0.8% | Aug 3, 2020 | Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license e... |
| CVE-2019-4589 | MEDIUM | 4.3 | 0.7% | Aug 3, 2020 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page ... |
| CVE-2019-4366 | MEDIUM | 5.3 | 0.7% | Aug 3, 2020 | IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gai... |
| CVE-2019-11286 | CRITICAL | 9.1 | 1.8% | Jul 31, 2020 | VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.1... |
| CVE-2019-14130 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in S... |
| CVE-2019-14124 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Co... |
| CVE-2019-14123 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HL... |
| CVE-2019-14101 | HIGH | 7.1 | 0.2% | Jul 30, 2020 | Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is... |
| CVE-2019-14100 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdrago... |
| CVE-2019-14099 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdra... |
| CVE-2019-14093 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon ... |
| CVE-2019-14037 | HIGH | 7.8 | 0.2% | Jul 30, 2020 | Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Comput... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now