2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9183HIGH7.5An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. A buffer overflow is present due to an intege...
CVE-2019-8359CRITICAL9.8An issue was discovered in Contiki-NG through 4.3 and Contiki through 3.0. An out of bounds write is present in the data...
CVE-2019-4735MEDIUM4.6IBM MaaS360 3.96.62 for iOS could allow an attacker with physical access to the device to obtain sensitive information f...
CVE-2019-4668MEDIUM5.5IBM UrbanCode Deploy (UCD) 7.0.4.0 stores user credentials in plain in clear text which can be read by a local user. IBM...
CVE-2019-6859HIGH7.5A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs ...
CVE-2019-20787CRITICAL9.8Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.
CVE-2019-19107MEDIUM5.5The Configuration pages in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway for user profiles and...
CVE-2019-19106CRITICAL9.1Improper implementation of Access Control in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway all...
CVE-2019-19105MEDIUM5.5The backup function in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway saves the current setting...
CVE-2019-19104CRITICAL9.8The web server in ABB Telephone Gateway TG/S 3.2 and Busch-Jaeger 6186/11 Telefon-Gateway allows access to different end...
CVE-2019-20102MEDIUM6.1The attachment-uploading feature in Atlassian Confluence Server from version 6.14.0 through version 6.14.3, and version ...
CVE-2019-4327HIGH7.5"HCL AppScan Enterprise uses hard-coded credentials which can be exploited by attackers to get unauthorized access to ap...
CVE-2019-17525HIGH8.8The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and...
CVE-2019-8961HIGH7.5A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16...
CVE-2019-8960HIGH7.5A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe versi...
CVE-2019-19108CRITICAL9.4An authentication weakness in the SNMP service in B&R Automation Runtime versions 2.96, 3.00, 3.01, 3.06 to 3.10, 4.00 t...
CVE-2019-10148——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12779. Reason: This candidate is a reservation d...
CVE-2019-20786CRITICAL9.8handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows ...
CVE-2019-2056MEDIUM5.5There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This could lead to local ...
CVE-2019-6203CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS ...
CVE-2019-4749MEDIUM5.4IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4644MEDIUM6.1IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2019-4446MEDIUM5.4IBM Maximo Asset Management 7.6 could allow an authenticated user perform actions they are not authorized to by modifyin...
CVE-2019-20785MEDIUM6.8An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radi...
CVE-2019-20784MEDIUM5.5An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Intera...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now