2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18382 | HIGH | 7.5 | 1.1% | Oct 23, 2019 | An issue was discovered on AVStar PE204 3.10.70 IP camera devices. A denial of service can occur on open TCP port 23456.... |
| CVE-2019-18371 | HIGH | 7.5 | 55.4% | Oct 23, 2019 | An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit... |
| CVE-2019-17093 | HIGH | 7.8 | 0.6% | Oct 23, 2019 | An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability all... |
| CVE-2019-11283 | HIGH | 8.8 | 1.5% | Oct 23, 2019 | Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote use... |
| CVE-2019-18280 | HIGH | 8.8 | 0.5% | Oct 23, 2019 | Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF... |
| CVE-2019-18278 | HIGH | 7.8 | 0.4% | Oct 23, 2019 | When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow st... |
| CVE-2019-18277 | HIGH | 7.5 | 10.0% | Oct 23, 2019 | A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chu... |
| CVE-2019-18220 | HIGH | 8.8 | 1.1% | Oct 23, 2019 | Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to valid... |
| CVE-2019-10476 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ma... |
| CVE-2019-10471 | HIGH | 8.8 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Libvirt Slaves Plugin allows attackers to connect to an attacker-s... |
| CVE-2019-10468 | HIGH | 8.8 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers to con... |
| CVE-2019-10466 | HIGH | 8.1 | 1.0% | Oct 23, 2019 | An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to... |
| CVE-2019-10464 | HIGH | 8.8 | 0.8% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Deploy WebLogic Plugin allows attackers to connect to an attacker-... |
| CVE-2019-10462 | HIGH | 8.1 | 0.7% | Oct 23, 2019 | A cross-site request forgery vulnerability in Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier allowed ... |
| CVE-2019-10461 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configura... |
| CVE-2019-10460 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration fil... |
| CVE-2019-12290 | HIGH | 7.5 | 2.8% | Oct 22, 2019 | GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels... |
| CVE-2019-10079 | HIGH | 7.5 | 4.6% | Oct 22, 2019 | Apache Traffic Server is vulnerable to HTTP/2 setting flood attacks. Earlier versions of Apache Traffic Server didn't li... |
| CVE-2019-4523 | HIGH | 7.8 | 0.4% | Oct 22, 2019 | IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds c... |
| CVE-2019-17424 | HIGH | 7.8 | 13.4% | Oct 22, 2019 | A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re... |
| CVE-2019-17400 | HIGH | 7.5 | 1.9% | Oct 21, 2019 | The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. |
| CVE-2019-16404 | HIGH | 8.8 | 1.1% | Oct 21, 2019 | Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract... |
| CVE-2019-17498 | HIGH | 8.1 | 3.8% | Oct 21, 2019 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds che... |
| CVE-2019-9491 | HIGH | 7.8 | 12.9% | Oct 21, 2019 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to... |
| CVE-2019-16965 | HIGH | 7.2 | 3.0% | Oct 21, 2019 | resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validat... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now