2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2569 | — | — | 0.4% | Jul 23, 2019 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, ... |
| CVE-2019-2561 | — | — | 1.4% | Jul 23, 2019 | Vulnerability in the Oracle Retail Xstore Office component of Oracle Retail Applications (subcomponent: Internal Operati... |
| CVE-2019-2484 | — | — | 0.7% | Jul 23, 2019 | Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5... |
| CVE-2019-12164 | — | — | 4.1% | Jul 23, 2019 | ubuntu-server.js in Status React Native Desktop before v0.57.8_mobile_ui allows Remote Code Execution. |
| CVE-2019-1010201 | — | — | 1.2% | Jul 23, 2019 | Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updatePr... |
| CVE-2019-1010200 | — | — | 1.9% | Jul 23, 2019 | Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is a... |
| CVE-2019-1010199 | — | — | 0.9% | Jul 23, 2019 | ServiceStack ServiceStack Framework 4.5.14 is affected by: Cross Site Scripting (XSS). The impact is: JavaScrpit is refl... |
| CVE-2019-13570 | — | — | 1.5% | Jul 23, 2019 | The AJdG AdRotate plugin before 5.3 for WordPress allows SQL Injection. |
| CVE-2019-12162 | — | — | 0.3% | Jul 23, 2019 | Upwork Time Tracker 5.2.2.716 doesn't verify the SHA256 hash of the downloaded program update before running it, which c... |
| CVE-2019-1010173 | — | — | 1.1% | Jul 23, 2019 | Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Js... |
| CVE-2019-9821 | — | — | 0.9% | Jul 23, 2019 | A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results... |
| CVE-2019-9820 | — | — | 1.6% | Jul 23, 2019 | A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results i... |
| CVE-2019-9819 | — | — | 1.7% | Jul 23, 2019 | A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a poten... |
| CVE-2019-9817 | — | — | 0.8% | Jul 23, 2019 | Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal imag... |
| CVE-2019-9816 | — | — | 6.2% | Jul 23, 2019 | A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, al... |
| CVE-2019-9815 | — | — | 1.8% | Jul 23, 2019 | If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has ... |
| CVE-2019-9814 | — | — | 1.3% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed ev... |
| CVE-2019-9800 | — | — | 1.8% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunde... |
| CVE-2019-11729 | — | — | 2.8% | Jul 23, 2019 | Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before b... |
| CVE-2019-11727 | — | — | 1.7% | Jul 23, 2019 | A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 ... |
| CVE-2019-11719 | — | — | 2.2% | Jul 23, 2019 | When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bou... |
| CVE-2019-11716 | — | — | 1.4% | Jul 23, 2019 | Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such a... |
| CVE-2019-11715 | — | — | 1.5% | Jul 23, 2019 | Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and le... |
| CVE-2019-11714 | — | — | 1.7% | Jul 23, 2019 | Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in som... |
| CVE-2019-11713 | — | — | 2.1% | Jul 23, 2019 | A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now