2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-12588MEDIUM6.5The client 802.11 mac implementation in Espressif ESP8266_NONOS_SDK 2.2.0 through 3.1.0 does not validate correctly the ...
CVE-2019-15902MEDIUM5.6A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.1...
CVE-2019-5478MEDIUM5.5A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices. This could lead to an adversary being able t...
CVE-2019-6182MEDIUM4.9A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that c...
CVE-2019-6181MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior...
CVE-2019-6180MEDIUM4.8A stored cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to...
CVE-2019-1125MEDIUM5.6An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. ...
CVE-2019-15889MEDIUM6.1The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t...
CVE-2019-3754MEDIUM4.7Dell EMC Unity Operating Environment versions prior to 5.0.0.0.5.116, Dell EMC UnityVSA versions prior to 5.0.0.0.5.116 ...
CVE-2019-3751MEDIUM6.4Dell EMC Enterprise Copy Data Management (eCDM) versions 1.0, 1.1, 2.0, 2.1, and 3.0 contain a certificate validation vu...
CVE-2019-10197MEDIUM6.5A flaw was found in samba versions 4.9.x up to 4.9.13, samba 4.10.x up to 4.10.8 and samba 4.11.x up to 4.11.0rc3, when ...
CVE-2019-2389MEDIUM4.2Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the...
CVE-2019-15833MEDIUM6.1The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
CVE-2019-1977MEDIUM6.8A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric ...
CVE-2019-1969MEDIUM5.3A vulnerability in the implementation of the Simple Network Management Protocol (SNMP) Access Control List (ACL) feature...
CVE-2019-15807MEDIUM4.7In the Linux kernel before 5.1.13, there is a memory leak in drivers/scsi/libsas/sas_expander.c when SAS expander discov...
CVE-2019-4536MEDIUM6.3IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror f...
CVE-2019-4133MEDIUM5.2IBM Cloud Automation Manager 3.1.2 could allow a malicious user on the client side (with access to client computer) to r...
CVE-2019-11476MEDIUM6.5An integer overflow in whoopsie before versions 0.2.52.5ubuntu0.1, 0.2.62ubuntu0.1, 0.2.64ubuntu0.1, 0.2.66, results in ...
CVE-2019-15759MEDIUM6.5An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer der...
CVE-2019-15758MEDIUM6.5An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Fai...
CVE-2019-11250MEDIUM6.5The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials ...
CVE-2019-11249MEDIUM6.5The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...
CVE-2019-11246MEDIUM6.5The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kub...
CVE-2019-11245MEDIUM4.9In kubelet v1.13.6 and v1.14.2, containers for pods that do not specify an explicit runAsUser attempt to run as uid 0 (r...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now