CVEs from 2019

3,286 normalized CVEs published or assigned in this year.

Total
3,286
critical
critical 204
high
high 479
medium
medium 471
low
low 94
% Critical
6.2%
% with KEV
3.6%
% with exploit
7.7%

Top vendors

Top products

  • u-boot 20
  • active_iq_unified_manager 7
  • jdk 5
  • weblogic_server 5
  • oncommand_workflow_automation 5
  • oncommand_insight 4
  • codeready_linux_builder_eus 4
  • libxslt 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-11580 unknown 2.5 5y ago Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.
CVE-2019-1215 unknown 2.5 5y ago Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker t…
CVE-2019-1429 unknown 2.5 5y ago Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
CVE-2019-0863 unknown 2.5 5y ago Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
CVE-2019-15949 unknown 2.5 5y ago Nagios XI contains a remote code execution vulnerability in which a user can modify the check_plugin executable and insert malicious commands to execute as root.
CVE-2019-18935 unknown 2.5 5y ago Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe proce…
CVE-2019-18988 unknown 2.5 5y ago TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key, they could decrypt p…
CVE-2019-9082 unknown 2.5 5y ago ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by…
CVE-2019-9978 unknown 2.5 5y ago WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
CVE-2019-16759 unknown 2.5 5y ago The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
CVE-2019-3398 unknown 2.5 5y ago Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can…
CVE-2019-0541 unknown 2.5 5y ago Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
CVE-2019-11539 unknown 2.5 5y ago Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
CVE-2019-20085 unknown 2.5 5y ago TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
CVE-2019-0808 unknown 2.5 5y ago Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.
CVE-2019-3396 unknown 2.5 5y ago Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.
CVE-2019-0708 unknown 2.5 5y ago Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send…
CVE-2019-0803 unknown 2.5 5y ago Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in k…
CVE-2019-0604 unknown 2.5 5y ago Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint applica…
CVE-2019-2215 unknown 2.5 5y ago Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-…
CVE-2019-1653 unknown 2.5 5y ago Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diag…
CVE-2019-15752 unknown 2.5 5y ago Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in %PROGRAMDATA%\DockerDesktop\version-bin\ as a low…
CVE-2019-4716 unknown 2.5 5y ago IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting.
CVE-2019-17402 low 2.5 5y ago RHSA-2021:1758: exiv2 security, bug fix, and enhancement update (Low)
CVE-2019-2708 low 2.5 5y ago RHSA-2021:1675: libdb security update (Low)
CVE-2019-18276 low 2.5 5y ago RHSA-2021:1679: bash security and bug fix update (Low)
CVE-2019-17450 low 2.5 6y ago RHSA-2020:4465: binutils security update (Low)
CVE-2019-1551 low 2.5 6y ago RHSA-2020:4514: openssl security, bug fix, and enhancement update (Low)
CVE-2019-20386 low 2.5 6y ago RHSA-2020:4553: systemd security, bug fix, and enhancement update (Low)
CVE-2019-16167 low 2.5 6y ago RHSA-2020:4638: sysstat security update (Low)
CVE-2019-14494 low 2.5 6y ago RHSA-2020:4643: poppler security update (Low)
CVE-2019-15165 low 2.5 6y ago RHSA-2020:4547: libpcap security, bug fix, and enhancement update (Low)
CVE-2019-1010305 low 2.5 6y ago RHSA-2020:1686: libmspack security and bug fix update (Low)
CVE-2019-13045 low 2.5 6y ago RHSA-2020:1616: irssi security update (Low)
CVE-2019-1010317 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010319 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-1010315 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-11498 low 2.5 6y ago RHSA-2020:1581: wavpack security update (Low)
CVE-2019-8696 low 2.5 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-1010204 low 2.5 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2019-3696 low 2.5 6y ago RHBA-2020:1628: pcp bug fix and enhancement update (Low)
CVE-2019-3695 low 2.5 6y ago RHBA-2020:1628: pcp bug fix and enhancement update (Low)
CVE-2019-19126 low 2.5 6y ago RHSA-2020:1828: glibc security, bug fix, and enhancement update (Low)
CVE-2019-17451 low 2.5 6y ago RHSA-2020:1797: binutils security and bug fix update (Low)
CVE-2019-8675 low 2.5 6y ago RHSA-2020:1765: cups security and bug fix update (Low)
CVE-2019-13232 low 2.5 6y ago RHSA-2020:1787: unzip security update (Low)
CVE-2019-14834 low 2.5 6y ago RHSA-2020:1715: dnsmasq security, bug fix, and enhancement update (Low)
CVE-2019-17558 unknown 2.5 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-19118 low 2.5 7y ago Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but ed…
CVE-2019-8726 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8768 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8735 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8536 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8524 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8666 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8610 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8535 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8544 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8608 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8551 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8609 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8615 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8607 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8559 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8619 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8601 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-11070 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-12795 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8677 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-6237 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-11459 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-3820 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-6251 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8523 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8563 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8571 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8583 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8584 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8586 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8587 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8594 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8595 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8596 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8597 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8673 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8687 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8676 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8679 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8681 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-8686 low 2.5 7y ago RHSA-2019:3553: GNOME security, bug fix, and enhancement update (Low)
CVE-2019-9824 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-12155 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-9755 low 2.5 7y ago RHSA-2019:3345: virt:rhel security, bug fix, and enhancement update (Low)
CVE-2019-1543 low 2.5 7y ago RHSA-2019:3700: openssl security, bug fix, and enhancement update (Low)
CVE-2019-7665 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-7664 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-10155 low 2.5 7y ago RHSA-2019:3391: libreswan security and bug fix update (Low)
CVE-2019-6465 low 2.5 7y ago RHSA-2019:3552: bind security and bug fix update (Low)
CVE-2019-7146 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)
CVE-2019-7150 low 2.5 7y ago RHSA-2019:3575: elfutils security, bug fix, and enhancement update (Low)