2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20029 | HIGH | 8.8 | 1.6% | Jul 29, 2020 | An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, includ... |
| CVE-2019-20028 | HIGH | 7.5 | 1.1% | Jul 29, 2020 | Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices ... |
| CVE-2019-20027 | CRITICAL | 9.8 | 1.4% | Jul 29, 2020 | Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain t... |
| CVE-2019-20026 | HIGH | 7.5 | 1.1% | Jul 29, 2020 | The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all ... |
| CVE-2019-20025 | CRITICAL | 9.8 | 2.9% | Jul 29, 2020 | Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an af... |
| CVE-2019-4731 | MEDIUM | 5.5 | 0.3% | Jul 28, 2020 | IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive ... |
| CVE-2019-18834 | MEDIUM | 6.1 | 1.6% | Jul 23, 2020 | Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arb... |
| CVE-2019-11252 | MEDIUM | 6.5 | 1.1% | Jul 23, 2020 | The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages i... |
| CVE-2019-16244 | CRITICAL | 9.8 | 1.2% | Jul 22, 2020 | OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query. |
| CVE-2019-18619 | HIGH | 7.8 | 0.5% | Jul 22, 2020 | Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prio... |
| CVE-2019-18618 | MEDIUM | 6 | 0.5% | Jul 22, 2020 | Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (al... |
| CVE-2019-12000 | MEDIUM | 6.6 | 1.1% | Jul 17, 2020 | HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when... |
| CVE-2019-4091 | MEDIUM | 5.4 | 0.5% | Jul 17, 2020 | "HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for ... |
| CVE-2019-4090 | MEDIUM | 5.4 | 0.5% | Jul 17, 2020 | "HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field." |
| CVE-2019-20915 | HIGH | 8.1 | 1.2% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_w... |
| CVE-2019-20914 | CRITICAL | 9.8 | 1.9% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_co... |
| CVE-2019-20913 | HIGH | 8.1 | 1.2% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_e... |
| CVE-2019-20912 | HIGH | 8.8 | 1.3% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly r... |
| CVE-2019-20911 | MEDIUM | 6.5 | 1.0% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in b... |
| CVE-2019-20910 | HIGH | 8.1 | 1.2% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decod... |
| CVE-2019-20909 | HIGH | 7.5 | 1.6% | Jul 16, 2020 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LW... |
| CVE-2019-4748 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2019-4747 | MEDIUM | 5.4 | 0.6% | Jul 16, 2020 | IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr... |
| CVE-2019-20908 | MEDIUM | 6.7 | 0.5% | Jul 15, 2020 | An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t... |
| CVE-2019-17639 | MEDIUM | 5.3 | 1.5% | Jul 15, 2020 | In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now