2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14815 | HIGH | 7.8 | 0.5% | Nov 25, 2019 | A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marve... |
| CVE-2019-10174 | HIGH | 8.8 | 3.1% | Nov 25, 2019 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allow... |
| CVE-2019-11287 | HIGH | 7.5 | 4.5% | Nov 23, 2019 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x ver... |
| CVE-2019-18909 | HIGH | 8 | 2.2% | Nov 22, 2019 | The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to ... |
| CVE-2019-3654 | HIGH | 8.6 | 0.7% | Nov 22, 2019 | Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l... |
| CVE-2019-18610 | HIGH | 8.8 | 29.6% | Nov 22, 2019 | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 1... |
| CVE-2019-17446 | HIGH | 7.8 | 0.3% | Nov 22, 2019 | An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operatio... |
| CVE-2019-18976 | HIGH | 7.5 | 6.7% | Nov 22, 2019 | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If i... |
| CVE-2019-3427 | HIGH | 7.2 | 1.1% | Nov 22, 2019 | The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exp... |
| CVE-2019-19013 | HIGH | 8.8 | 0.8% | Nov 22, 2019 | A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a ... |
| CVE-2019-13157 | HIGH | 7.5 | 1.7% | Nov 22, 2019 | nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences... |
| CVE-2019-18888 | HIGH | 7.5 | 2.2% | Nov 21, 2019 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4... |
| CVE-2019-18887 | HIGH | 8.1 | 1.3% | Nov 21, 2019 | An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4... |
| CVE-2019-19207 | HIGH | 8.8 | 22.7% | Nov 21, 2019 | rConfig 3.9.2 allows devices.php?searchColumn= SQL injection. |
| CVE-2019-19204 | HIGH | 7.5 | 6.9% | Nov 21, 2019 | An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as ... |
| CVE-2019-19203 | HIGH | 7.5 | 4.1% | Nov 21, 2019 | An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UCha... |
| CVE-2019-5637 | HIGH | 7.5 | 1.4% | Nov 21, 2019 | When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached b... |
| CVE-2019-5636 | HIGH | 7.5 | 1.4% | Nov 21, 2019 | When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi... |
| CVE-2019-19202 | HIGH | 8.8 | 1.0% | Nov 21, 2019 | In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to c... |
| CVE-2019-19197 | HIGH | 7.8 | 0.6% | Nov 21, 2019 | IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escala... |
| CVE-2019-19191 | HIGH | 7.8 | 0.5% | Nov 21, 2019 | Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlle... |
| CVE-2019-16758 | HIGH | 7.5 | 16.8% | Nov 21, 2019 | In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech... |
| CVE-2019-16406 | HIGH | 7.8 | 0.5% | Nov 21, 2019 | Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual ma... |
| CVE-2019-16405 | HIGH | 7.2 | 27.0% | Nov 21, 2019 | Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code... |
| CVE-2019-15511 | HIGH | 7.8 | 0.7% | Nov 21, 2019 | An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now