2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15890 | HIGH | 7.5 | 4.0% | Sep 6, 2019 | libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c. |
| CVE-2019-5069 | HIGH | 8.8 | 2.3% | Sep 5, 2019 | A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe ... |
| CVE-2019-15949 | HIGH | 8.8 | 77.7% | Sep 5, 2019 | Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios ... |
| CVE-2019-15947 | HIGH | 7.5 | 1.4% | Sep 5, 2019 | In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. ... |
| CVE-2019-15942 | HIGH | 8.8 | 2.0% | Sep 5, 2019 | FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rb... |
| CVE-2019-4321 | HIGH | 7.5 | 1.5% | Sep 5, 2019 | IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V... |
| CVE-2019-1939 | HIGH | 8.8 | 4.7% | Sep 5, 2019 | A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute a... |
| CVE-2019-12645 | HIGH | 7.8 | 0.3% | Sep 5, 2019 | A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac c... |
| CVE-2019-12633 | HIGH | 7.5 | 1.5% | Sep 5, 2019 | A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to... |
| CVE-2019-12632 | HIGH | 7.5 | 1.6% | Sep 5, 2019 | A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a... |
| CVE-2019-15927 | HIGH | 7.8 | 0.4% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_pr... |
| CVE-2019-15925 | HIGH | 7.8 | 0.3% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.2.3. An out of bounds access exists in the function hclge_tm_schd_m... |
| CVE-2019-15918 | HIGH | 7.8 | 0.6% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.10. SMB2_negotiate in fs/cifs/smb2pdu.c has an out-of-bounds read... |
| CVE-2019-15917 | HIGH | 7 | 0.7% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() f... |
| CVE-2019-6643 | HIGH | 7.5 | 1.3% | Sep 4, 2019 | On versions 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, and 11.5.2-11.6.4, an attacker sending spe... |
| CVE-2019-6645 | HIGH | 7.5 | 1.3% | Sep 4, 2019 | On BIG-IP 14.0.0-14.1.0.5, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, FTP traffic passing through a Virtual Server w... |
| CVE-2019-15916 | HIGH | 7.5 | 3.8% | Sep 4, 2019 | An issue was discovered in the Linux kernel before 5.0.1. There is a memory leak in register_queue_kobjects() in net/cor... |
| CVE-2019-13522 | HIGH | 7.8 | 1.4% | Sep 4, 2019 | An attacker could use a specially crafted project file to corrupt the memory and execute code under the privileges of th... |
| CVE-2019-15813 | HIGH | 8.8 | 33.2% | Sep 4, 2019 | Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb... |
| CVE-2019-15903 | HIGH | 7.5 | 6.6% | Sep 4, 2019 | In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too... |
| CVE-2019-5479 | HIGH | 7.5 | 1.3% | Sep 3, 2019 | An unintended require vulnerability in <v0.5.5 larvitbase-api may allow an attacker to load arbitrary non-production cod... |
| CVE-2019-6179 | HIGH | 7.5 | 1.4% | Sep 3, 2019 | An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to vers... |
| CVE-2019-14817 | HIGH | 7.8 | 2.0% | Sep 3, 2019 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not prop... |
| CVE-2019-14811 | HIGH | 7.8 | 3.8% | Sep 3, 2019 | A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properl... |
| CVE-2019-13156 | HIGH | 7.5 | 1.0% | Sep 3, 2019 | NDrive(1.2.2).sys in Naver Cloud Explorer has a stack-based buffer overflow, which allows attackers to cause a denial of... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now