2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-15739MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown...
CVE-2019-15738MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Under certain conditions, merge ...
CVE-2019-15737MEDIUM6.5An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Certain account actions needed improv...
CVE-2019-15734MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 8.6 through 12.2.1. Under very specific conditions, c...
CVE-2019-15733MEDIUM4.3An issue was discovered in GitLab Community and Enterprise Edition 7.12 through 12.2.1. The specified default branch nam...
CVE-2019-15732MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be ...
CVE-2019-15731MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment...
CVE-2019-15727MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.2 through 12.2.1. Insufficient permission checks w...
CVE-2019-15726MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in ma...
CVE-2019-15724MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerab...
CVE-2019-15723MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests cre...
CVE-2019-15721MEDIUM5.4An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintention...
CVE-2019-13140MEDIUM6.5Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" accoun...
CVE-2019-15950MEDIUM6.1The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
CVE-2019-11184MEDIUM4.8A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated u...
CVE-2019-11166MEDIUM6.7Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authe...
CVE-2019-16355MEDIUM5.5The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for indivi...
CVE-2019-16354MEDIUM4.7The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition invo...
CVE-2019-16352MEDIUM6.5ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
CVE-2019-16351MEDIUM6.5ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
CVE-2019-16350MEDIUM6.5ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
CVE-2019-16349MEDIUM5.5Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from t...
CVE-2019-16348MEDIUM6.5marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
CVE-2019-16197MEDIUM6.1In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document ...
CVE-2019-16334MEDIUM4.8In Bludit v3.9.2, there is a persistent XSS vulnerability in the Categories -> Add New Category -> Name field. NOTE: thi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now