2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16884 | HIGH | 7.5 | 4.4% | Sep 25, 2019 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass beca... |
| CVE-2019-16882 | HIGH | 7.5 | 1.5% | Sep 25, 2019 | An issue was discovered in the string-interner crate before 0.7.1 for Rust. It allows attackers to read from memory loca... |
| CVE-2019-16188 | HIGH | 7.1 | 0.8% | Sep 25, 2019 | HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particul... |
| CVE-2019-16701 | HIGH | 8.8 | 19.6% | Sep 25, 2019 | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph... |
| CVE-2019-10428 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Aqua Security Scanner Plugin 3.0.17 and earlier transmitted configured credentials in plain text as part of the ... |
| CVE-2019-10412 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenki... |
| CVE-2019-10411 | HIGH | 7.5 | 0.9% | Sep 25, 2019 | Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the globa... |
| CVE-2019-5094 | HIGH | 7.5 | 1.1% | Sep 24, 2019 | An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially craf... |
| CVE-2019-13527 | HIGH | 7.8 | 5.3% | Sep 24, 2019 | In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Aren... |
| CVE-2019-16754 | HIGH | 7.5 | 1.5% | Sep 24, 2019 | RIOT 2019.07 contains a NULL pointer dereference in the MQTT-SN implementation (asymcute), potentially allowing an attac... |
| CVE-2019-14753 | HIGH | 7.5 | 1.2% | Sep 24, 2019 | SICK FX0-GPNT00000 and FX0-GENT00000 devices through 3.4.0 have a Buffer Overflow |
| CVE-2019-13357 | HIGH | 7.8 | 0.6% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, resource acquisition from the untrusted search path C:\ used by caschelp.exe allo... |
| CVE-2019-13356 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-13355 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS... |
| CVE-2019-16729 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all... |
| CVE-2019-10754 | HIGH | 8.1 | 1.8% | Sep 23, 2019 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for... |
| CVE-2019-1367 | HIGH | 7.5 | 52.7% | Sep 23, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-1255 | HIGH | 7.5 | 3.9% | Sep 23, 2019 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denia... |
| CVE-2019-11277 | HIGH | 8.1 | 1.7% | Sep 23, 2019 | Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP ... |
| CVE-2019-10996 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10984 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10978 | HIGH | 7.8 | 0.9% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-13063 | HIGH | 7.5 | 27.2% | Sep 23, 2019 | Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc... |
| CVE-2019-16720 | HIGH | 7.5 | 1.4% | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 does not properly restrict file upload in plugins/ueditor/php/controller.php?upfolder=news&action=c... |
| CVE-2019-16718 | HIGH | 7.8 | 2.3% | Sep 23, 2019 | In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now