2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11497 | HIGH | 7.5 | 0.7% | Sep 10, 2019 | In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDC... |
| CVE-2019-11467 | HIGH | 7.5 | 1.3% | Sep 10, 2019 | In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index ... |
| CVE-2019-12105 | HIGH | 8.2 | 2.3% | Sep 10, 2019 | In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer respo... |
| CVE-2019-0365 | HIGH | 7.5 | 1.4% | Sep 10, 2019 | SAP Kernel (RFC), KRNL32NUC, KRNL32UC and KRNL64NUC before versions 7.21, 7.21EXT, 7.22, 7.22EXT, KRNL64UC, before versi... |
| CVE-2019-0363 | HIGH | 7.1 | 0.9% | Sep 10, 2019 | Attackers may misuse an HTTP/REST endpoint of SAP HANA Extended Application Services (Advanced model), before version 1.... |
| CVE-2019-0355 | HIGH | 7.2 | 1.6% | Sep 10, 2019 | SAP NetWeaver Application Server Java Web Container, ENGINEAPI (before versions 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) and ... |
| CVE-2019-0352 | HIGH | 7.5 | 1.1% | Sep 10, 2019 | In SAP Business Objects Business Intelligence Platform, before versions 4.1, 4.2 and 4.3, some dynamic pages (like jsp) ... |
| CVE-2019-16106 | HIGH | 7.5 | 1.1% | Sep 10, 2019 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the p... |
| CVE-2019-12401 | HIGH | 7.5 | 7.5% | Sep 10, 2019 | Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resource consumption attack (a... |
| CVE-2019-16187 | HIGH | 7.5 | 1.4% | Sep 9, 2019 | Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie ... |
| CVE-2019-16186 | HIGH | 7.2 | 1.3% | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. |
| CVE-2019-16185 | HIGH | 7.2 | 1.3% | Sep 9, 2019 | In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. |
| CVE-2019-16177 | HIGH | 7.5 | 1.5% | Sep 9, 2019 | In Limesurvey before 3.17.14, the entire database is exposed through browser caching. |
| CVE-2019-16174 | HIGH | 8.8 | 2.4% | Sep 9, 2019 | An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially c... |
| CVE-2019-6793 | HIGH | 7 | 3.5% | Sep 9, 2019 | An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The ... |
| CVE-2019-6788 | HIGH | 7.5 | 4.3% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-6783 | HIGH | 8.8 | 5.5% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-6782 | HIGH | 7.5 | 1.8% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-11605 | HIGH | 7.5 | 1.2% | Sep 9, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.... |
| CVE-2019-5473 | HIGH | 7.2 | 1.7% | Sep 9, 2019 | An authentication issue was discovered in GitLab that allowed a bypass of email verification. This was addressed in GitL... |
| CVE-2019-16163 | HIGH | 7.5 | 2.8% | Sep 9, 2019 | Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. |
| CVE-2019-16162 | HIGH | 7.5 | 1.8% | Sep 9, 2019 | Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c. |
| CVE-2019-16161 | HIGH | 7.5 | 2.1% | Sep 9, 2019 | Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c. |
| CVE-2019-16159 | HIGH | 7.5 | 3.2% | Sep 9, 2019 | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon... |
| CVE-2019-12465 | HIGH | 8.1 | 1.2% | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now