2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13052 | — | — | 0.7% | Jun 29, 2019 | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. |
| CVE-2019-13049 | — | — | 0.5% | Jun 29, 2019 | An integer wrap in kernel/sys/syscall.c in ToaruOS 1.10.10 allows users to map arbitrary kernel pages into userland proc... |
| CVE-2019-13048 | — | — | 0.4% | Jun 29, 2019 | kernel/sys/syscall.c in ToaruOS through 1.10.9 allows a denial of service upon a critical error in certain sys_sbrk allo... |
| CVE-2019-13047 | — | — | 0.5% | Jun 29, 2019 | kernel/sys/syscall.c in ToaruOS through 1.10.9 has incorrect access control in sys_sysfunc case 9 for TOARU_SYS_FUNC_SET... |
| CVE-2019-13046 | — | — | 0.5% | Jun 29, 2019 | linker/linker.c in ToaruOS through 1.10.9 has insecure LD_LIBRARY_PATH handling in setuid applications. |
| CVE-2019-13045 | — | — | 3.3% | Jun 29, 2019 | Irssi before 1.0.8, 1.1.x before 1.1.3, and 1.2.x before 1.2.1, when SASL is enabled, has a use after free when sending ... |
| CVE-2019-13044 | — | — | — | Jun 29, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13035 | — | — | 0.4% | Jun 29, 2019 | Artica Pandora FMS 7.0 NG before 735 suffers from local privilege escalation due to improper permissions on C:\PandoraFM... |
| CVE-2019-13032 | — | — | 1.0% | Jun 28, 2019 | An issue was discovered in FlightCrew v0.9.2 and earlier. A NULL pointer dereference occurs in GetRelativePathToNcx() or... |
| CVE-2019-13031 | — | — | 1.9% | Jun 28, 2019 | LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification se... |
| CVE-2019-13028 | — | — | 3.7% | Jun 28, 2019 | An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.... |
| CVE-2019-9843 | — | — | 1.5% | Jun 28, 2019 | In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would re... |
| CVE-2019-12932 | — | — | 0.8% | Jun 28, 2019 | A stored XSS vulnerability was found in SeedDMS 5.1.11 due to poorly escaping the search result in the autocomplete sear... |
| CVE-2019-4369 | — | — | — | Jun 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9846 | — | — | 1.7% | Jun 28, 2019 | RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreesto... |
| CVE-2019-13012 | — | — | 3.2% | Jun 28, 2019 | The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_w... |
| CVE-2019-12997 | — | — | 2.1% | Jun 28, 2019 | In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment... |
| CVE-2019-12995 | — | — | 2.2% | Jun 28, 2019 | Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is rel... |
| CVE-2019-5785 | — | — | 1.2% | Jun 27, 2019 | Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an ... |
| CVE-2019-5784 | — | — | 1.6% | Jun 27, 2019 | Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentiall... |
| CVE-2019-12581 | — | — | 6.4% | Jun 27, 2019 | A reflective Cross-site scripting (XSS) vulnerability in the free_time_failed.cgi CGI program in selected Zyxel ZyWall, ... |
| CVE-2019-12887 | — | — | 1.2% | Jun 27, 2019 | KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Control (issue 1 of 2). |
| CVE-2019-12583 | — | — | 43.9% | Jun 27, 2019 | Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attack... |
| CVE-2019-9039 | — | — | 2.7% | Jun 26, 2019 | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additio... |
| CVE-2019-12984 | — | — | 2.3% | Jun 26, 2019 | A NULL pointer dereference vulnerability in the function nfc_genl_deactivate_target() in net/nfc/netlink.c in the Linux ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now