2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11712 | — | — | 1.0% | Jul 23, 2019 | POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirem... |
| CVE-2019-11702 | — | — | 1.4% | Jul 23, 2019 | A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a kn... |
| CVE-2019-11701 | — | — | 0.6% | Jul 23, 2019 | The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default... |
| CVE-2019-11700 | — | — | 1.4% | Jul 23, 2019 | A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user a... |
| CVE-2019-11699 | — | — | 0.8% | Jul 23, 2019 | A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page nav... |
| CVE-2019-11698 | — | — | 1.4% | Jul 23, 2019 | If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently ... |
| CVE-2019-11697 | — | — | 0.8% | Jul 23, 2019 | If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed... |
| CVE-2019-11696 | — | — | 0.8% | Jul 23, 2019 | Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download... |
| CVE-2019-11695 | — | — | 0.7% | Jul 23, 2019 | A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when i... |
| CVE-2019-11694 | — | — | 1.5% | Jul 23, 2019 | A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a ... |
| CVE-2019-11693 | — | — | 2.4% | Jul 23, 2019 | The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could ... |
| CVE-2019-11692 | — | — | 1.6% | Jul 23, 2019 | A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, ... |
| CVE-2019-11691 | — | — | 1.6% | Jul 23, 2019 | A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main t... |
| CVE-2019-1010221 | — | — | 0.4% | Jul 23, 2019 | LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` c... |
| CVE-2019-1010209 | — | — | 2.1% | Jul 23, 2019 | GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized ... |
| CVE-2019-1010208 | — | — | 0.5% | Jul 23, 2019 | IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffe... |
| CVE-2019-1010207 | — | — | 1.5% | Jul 23, 2019 | Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session coo... |
| CVE-2019-1010205 | — | — | 2.8% | Jul 23, 2019 | LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact... |
| CVE-2019-1010202 | — | — | 1.3% | Jul 23, 2019 | Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component ... |
| CVE-2019-1010171 | — | — | 1.1% | Jul 23, 2019 | Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference. The impact is: denial of service. The component is: functio... |
| CVE-2019-1010170 | — | — | 1.1% | Jul 23, 2019 | Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_Obj... |
| CVE-2019-1010169 | — | — | 1.4% | Jul 23, 2019 | Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read. The impact is: denial of service. The component is: function lex... |
| CVE-2019-1010162 | — | — | 0.8% | Jul 23, 2019 | jsish 2.4.74 2.0474 is affected by: CWE-476: NULL Pointer Dereference. The impact is: denial of service. The component i... |
| CVE-2019-1010156 | — | — | — | Jul 23, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-1010155. Reason: This candidate is a duplicate o... |
| CVE-2019-1010153 | — | — | 1.5% | Jul 23, 2019 | zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now