2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19456 | MEDIUM | 6.1 | 1.0% | May 18, 2020 | A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza ... |
| CVE-2019-19454 | HIGH | 7.5 | 1.6% | May 18, 2020 | An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue ... |
| CVE-2019-7247 | CRITICAL | 9.8 | 2.1% | May 18, 2020 | An issue was discovered in AODDriver2.sys in AMD OverDrive. The vulnerable driver exposes a wrmsr instruction via IOCTL ... |
| CVE-2019-7246 | MEDIUM | 6.7 | 0.4% | May 18, 2020 | An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. T... |
| CVE-2019-20802 | MEDIUM | 6.1 | 0.7% | May 18, 2020 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server im... |
| CVE-2019-20801 | MEDIUM | 5.3 | 1.0% | May 18, 2020 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al... |
| CVE-2019-20800 | CRITICAL | 9.8 | 2.1% | May 18, 2020 | In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in... |
| CVE-2019-20799 | HIGH | 7.5 | 2.4% | May 18, 2020 | In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work ... |
| CVE-2019-20798 | HIGH | 8.4 | 1.7% | May 18, 2020 | An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displa... |
| CVE-2019-20797 | HIGH | 7.5 | 2.7% | May 18, 2020 | An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for... |
| CVE-2019-20390 | HIGH | 8.1 | 0.7% | May 15, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to r... |
| CVE-2019-20389 | MEDIUM | 6.1 | 0.9% | May 15, 2020 | An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can i... |
| CVE-2019-19721 | HIGH | 7.8 | 1.9% | May 15, 2020 | An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows re... |
| CVE-2019-18666 | CRITICAL | 9.8 | 3.2% | May 15, 2020 | An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without autho... |
| CVE-2019-17572 | MEDIUM | 5.3 | 3.0% | May 14, 2020 | In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topi... |
| CVE-2019-17562 | CRITICAL | 9.8 | 2.9% | May 14, 2020 | A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all vers... |
| CVE-2019-13023 | MEDIUM | 6.5 | 0.8% | May 14, 2020 | An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD... |
| CVE-2019-13022 | CRITICAL | 9.8 | 1.3% | May 14, 2020 | Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorit... |
| CVE-2019-13021 | MEDIUM | 6.5 | 0.6% | May 14, 2020 | The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem,... |
| CVE-2019-15083 | MEDIUM | 6.1 | 6.3% | May 14, 2020 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst... |
| CVE-2019-2388 | MEDIUM | 5.3 | 1.0% | May 13, 2020 | In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access l... |
| CVE-2019-9682 | HIGH | 8.1 | 0.9% | May 13, 2020 | Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compati... |
| CVE-2019-15880 | CRITICAL | 9.8 | 1.5% | May 13, 2020 | In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocat... |
| CVE-2019-15879 | HIGH | 7.4 | 0.7% | May 13, 2020 | In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a... |
| CVE-2019-15878 | HIGH | 7.8 | 0.3% | May 13, 2020 | In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now