2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11261 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11260 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11259 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11258 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11257 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-11256 | — | — | — | Feb 3, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: The CNA or individual who requested this candidate did not as... |
| CVE-2019-18193 | HIGH | 7.5 | 0.3% | Feb 3, 2020 | In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain co... |
| CVE-2019-20446 | MEDIUM | 6.5 | 2.1% | Feb 2, 2020 | In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passe... |
| CVE-2019-3016 | MEDIUM | 4.7 | 0.6% | Jan 31, 2020 | In a Linux KVM guest that has PV TLB enabled, a process in the guest kernel may be able to read memory locations from an... |
| CVE-2019-13000 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states... |
| CVE-2019-12999 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control. |
| CVE-2019-12998 | HIGH | 7.5 | 1.8% | Jan 31, 2020 | c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md ... |
| CVE-2019-4720 | HIGH | 7.5 | 2.2% | Jan 31, 2020 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia... |
| CVE-2019-19550 | HIGH | 7.5 | 1.9% | Jan 31, 2020 | Remote Authentication Bypass in Senior Rubiweb 6.2.34.28 and 6.2.34.37 allows admin access to sensitive information of a... |
| CVE-2019-18913 | MEDIUM | 6.8 | 0.6% | Jan 31, 2020 | A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks.... |
| CVE-2019-10782 | MEDIUM | 5.3 | 1.5% | Jan 30, 2020 | All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to... |
| CVE-2019-20358 | HIGH | 7.8 | 4.6% | Jan 30, 2020 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to... |
| CVE-2019-17273 | MEDIUM | 6.5 | 0.7% | Jan 30, 2020 | E-Series SANtricity OS Controller Software version 11.60.0 is susceptible to a vulnerability which allows an attacker to... |
| CVE-2019-20050 | MEDIUM | 6.8 | 3.4% | Jan 30, 2020 | Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated us... |
| CVE-2019-10783 | CRITICAL | 9.8 | 2.6% | Jan 29, 2020 | All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the p... |
| CVE-2019-20445 | CRITICAL | 9.1 | 13.5% | Jan 29, 2020 | HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Lengt... |
| CVE-2019-20444 | CRITICAL | 9.1 | 8.7% | Jan 29, 2020 | HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a ... |
| CVE-2019-18634 | HIGH | 7.8 | 19.4% | Jan 29, 2020 | In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the ... |
| CVE-2019-7656 | HIGH | 7.8 | 0.5% | Jan 29, 2020 | A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to e... |
| CVE-2019-7655 | MEDIUM | 5.4 | 0.9% | Jan 29, 2020 | Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.v... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now