2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20801 | MEDIUM | 5.3 | 1.0% | May 18, 2020 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al... |
| CVE-2019-20800 | CRITICAL | 9.8 | 2.1% | May 18, 2020 | In Cherokee through 1.2.104, remote attackers can trigger an out-of-bounds write in cherokee_handler_cgi_add_env_pair in... |
| CVE-2019-20799 | HIGH | 7.5 | 2.4% | May 18, 2020 | In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work ... |
| CVE-2019-20798 | HIGH | 8.4 | 1.7% | May 18, 2020 | An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displa... |
| CVE-2019-20797 | HIGH | 7.5 | 2.7% | May 18, 2020 | An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for... |
| CVE-2019-20390 | HIGH | 8.1 | 0.7% | May 15, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to r... |
| CVE-2019-20389 | MEDIUM | 6.1 | 0.9% | May 15, 2020 | An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can i... |
| CVE-2019-19721 | HIGH | 7.8 | 1.9% | May 15, 2020 | An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows re... |
| CVE-2019-18666 | CRITICAL | 9.8 | 3.2% | May 15, 2020 | An issue was discovered on D-Link DAP-1360 revision F devices. Remote attackers can start a telnet service without autho... |
| CVE-2019-17572 | MEDIUM | 5.3 | 3.0% | May 14, 2020 | In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topi... |
| CVE-2019-17562 | CRITICAL | 9.8 | 2.9% | May 14, 2020 | A buffer overflow vulnerability has been found in the baremetal component of Apache CloudStack. This applies to all vers... |
| CVE-2019-13023 | MEDIUM | 6.5 | 0.8% | May 14, 2020 | An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD... |
| CVE-2019-13022 | CRITICAL | 9.8 | 1.3% | May 14, 2020 | Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorit... |
| CVE-2019-13021 | MEDIUM | 6.5 | 0.6% | May 14, 2020 | The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem,... |
| CVE-2019-15083 | MEDIUM | 6.1 | 6.3% | May 14, 2020 | Default installations of Zoho ManageEngine ServiceDesk Plus 10.0 before 10500 are vulnerable to XSS injected by a workst... |
| CVE-2019-2388 | MEDIUM | 5.3 | 1.0% | May 13, 2020 | In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access l... |
| CVE-2019-9682 | HIGH | 8.1 | 0.9% | May 13, 2020 | Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compati... |
| CVE-2019-15880 | CRITICAL | 9.8 | 1.5% | May 13, 2020 | In FreeBSD 12.1-STABLE before r356911, and 12.1-RELEASE before p5, insufficient checking in the cryptodev module allocat... |
| CVE-2019-15879 | HIGH | 7.4 | 0.7% | May 13, 2020 | In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a... |
| CVE-2019-15878 | HIGH | 7.8 | 0.3% | May 13, 2020 | In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use... |
| CVE-2019-16112 | HIGH | 8.8 | 11.4% | May 13, 2020 | TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java objec... |
| CVE-2019-4478 | MEDIUM | 6.5 | 1.0% | May 12, 2020 | IBM Maximo Asset Management 7.6.0, and 7.6.1 could allow an authenticated user to obtain highly sensitive information th... |
| CVE-2019-5500 | HIGH | 7.5 | 1.8% | May 11, 2020 | Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthentic... |
| CVE-2019-4667 | MEDIUM | 5.9 | 0.8% | May 11, 2020 | IBM UrbanCode Deploy (UCD) 7.0.5.2 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2019-19162 | HIGH | 7.8 | 1.2% | May 11, 2020 | A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system ru... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now