2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11665 | HIGH | 7.5 | 1.1% | Sep 17, 2019 | Data exposure in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51... |
| CVE-2019-4183 | HIGH | 7.5 | 3.5% | Sep 17, 2019 | IBM Cognos Analytics 11.0, and 11.1 is vulnerable to a denial of service attack that could allow a remote user to send s... |
| CVE-2019-4175 | HIGH | 7.5 | 1.0% | Sep 17, 2019 | IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2019-11666 | HIGH | 8.8 | 1.2% | Sep 17, 2019 | Insecure deserialization of untrusted data in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34,... |
| CVE-2019-11667 | HIGH | 7.5 | 1.1% | Sep 17, 2019 | Unauthorized access to contact information in Micro Focus Service Manager, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, ... |
| CVE-2019-9009 | HIGH | 7.5 | 1.7% | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash... |
| CVE-2019-14835 | HIGH | 7.8 | 0.6% | Sep 17, 2019 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that t... |
| CVE-2019-15729 | HIGH | 7.5 | 1.7% | Sep 17, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintention... |
| CVE-2019-9008 | HIGH | 8.8 | 1.9% | Sep 17, 2019 | An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over ... |
| CVE-2019-4147 | HIGH | 7.2 | 1.3% | Sep 16, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 is vulnerable to SQL injection. A remote attacker could send specially... |
| CVE-2019-16371 | HIGH | 8.2 | 1.2% | Sep 16, 2019 | LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a vict... |
| CVE-2019-15736 | HIGH | 7.5 | 2.0% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Under certain circumstances, CI pipel... |
| CVE-2019-8371 | HIGH | 7.2 | 2.6% | Sep 16, 2019 | OpenEMR v5.0.1-6 allows code execution. |
| CVE-2019-15730 | HIGH | 7.5 | 1.5% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.14 through 12.2.1. The Jira integration contains a ... |
| CVE-2019-15728 | HIGH | 7.5 | 1.5% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.1 through 12.2.1. Protections against SSRF attacks... |
| CVE-2019-15725 | HIGH | 7.5 | 1.8% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API th... |
| CVE-2019-15722 | HIGH | 7.5 | 1.9% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressi... |
| CVE-2019-0207 | HIGH | 7.5 | 3.1% | Sep 16, 2019 | Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, w... |
| CVE-2019-16353 | HIGH | 7.5 | 1.4% | Sep 16, 2019 | Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic f... |
| CVE-2019-16347 | HIGH | 8.8 | 1.5% | Sep 16, 2019 | ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinte... |
| CVE-2019-16346 | HIGH | 8.8 | 1.6% | Sep 16, 2019 | ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinter... |
| CVE-2019-16170 | HIGH | 7.1 | 1.0% | Sep 16, 2019 | An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x befor... |
| CVE-2019-16319 | HIGH | 7.5 | 3.8% | Sep 15, 2019 | In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addresse... |
| CVE-2019-16318 | HIGH | 8.8 | 1.4% | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character ... |
| CVE-2019-16317 | HIGH | 8.8 | 1.7% | Sep 14, 2019 | In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now