2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8127 | HIGH | 8.8 | 1.3% | Nov 5, 2019 | A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenti... |
| CVE-2019-8125 | HIGH | 7.2 | 1.7% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can mod... |
| CVE-2019-8122 | HIGH | 8.8 | 1.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 pr... |
| CVE-2019-8119 | HIGH | 7.2 | 1.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 pr... |
| CVE-2019-8116 | HIGH | 7.5 | 1.9% | Nov 5, 2019 | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to... |
| CVE-2019-8114 | HIGH | 7.2 | 1.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Ma... |
| CVE-2019-8112 | HIGH | 7.5 | 0.6% | Nov 5, 2019 | A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauth... |
| CVE-2019-8111 | HIGH | 8.8 | 1.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ... |
| CVE-2019-8110 | HIGH | 8.8 | 1.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ... |
| CVE-2019-8109 | HIGH | 8 | 0.9% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ... |
| CVE-2019-8093 | HIGH | 8.8 | 1.1% | Nov 5, 2019 | An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An... |
| CVE-2019-8091 | HIGH | 7.2 | 1.7% | Nov 5, 2019 | A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user wit... |
| CVE-2019-5089 | HIGH | 7.8 | 2.0% | Nov 5, 2019 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially c... |
| CVE-2019-5088 | HIGH | 7.8 | 2.0% | Nov 5, 2019 | An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially ... |
| CVE-2019-16284 | HIGH | 7.2 | 2.0% | Nov 5, 2019 | A potential security vulnerability has been identified in multiple HP products and versions which involves possible exec... |
| CVE-2019-10084 | HIGH | 7.5 | 1.0% | Nov 5, 2019 | In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can i... |
| CVE-2019-1789 | HIGH | 7.5 | 1.5% | Nov 5, 2019 | ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read ... |
| CVE-2019-15966 | HIGH | 7.7 | 1.2% | Nov 5, 2019 | A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote... |
| CVE-2019-12625 | HIGH | 7.5 | 2.2% | Nov 5, 2019 | ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause... |
| CVE-2019-18631 | HIGH | 7.8 | 1.2% | Nov 5, 2019 | The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5... |
| CVE-2019-17062 | HIGH | 8.8 | 1.2% | Nov 5, 2019 | An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2... |
| CVE-2019-17598 | HIGH | 7.5 | 0.7% | Nov 5, 2019 | An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an auth... |
| CVE-2019-17221 | HIGH | 7.5 | 3.4% | Nov 5, 2019 | PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI... |
| CVE-2019-3685 | HIGH | 7.7 | 0.7% | Nov 5, 2019 | Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client bi... |
| CVE-2019-18178 | HIGH | 7.5 | 0.9% | Nov 4, 2019 | Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now