2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15858 | HIGH | 8.8 | 20.8% | Sep 3, 2019 | admin/includes/class.import.snippet.php in the "Woody ad snippets" plugin before 2.2.5 for WordPress allows unauthentica... |
| CVE-2019-15847 | HIGH | 7.5 | 3.2% | Sep 2, 2019 | The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_dar... |
| CVE-2019-2390 | HIGH | 7.8 | 1.0% | Aug 30, 2019 | An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location ma... |
| CVE-2019-5612 | HIGH | 7.5 | 0.9% | Aug 30, 2019 | In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE be... |
| CVE-2019-5611 | HIGH | 7.5 | 4.4% | Aug 30, 2019 | In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE be... |
| CVE-2019-5610 | HIGH | 7.5 | 3.8% | Aug 30, 2019 | In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE bef... |
| CVE-2019-5609 | HIGH | 7.5 | 1.3% | Aug 30, 2019 | In FreeBSD 12.0-STABLE before r350619, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350619, 11.3-RELEASE bef... |
| CVE-2019-1968 | HIGH | 7.5 | 1.8% | Aug 30, 2019 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a... |
| CVE-2019-1967 | HIGH | 7.5 | 2.0% | Aug 30, 2019 | A vulnerability in the Network Time Protocol (NTP) feature of Cisco NX-OS Software could allow an unauthenticated, remot... |
| CVE-2019-1966 | HIGH | 7.8 | 0.4% | Aug 30, 2019 | A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Intercon... |
| CVE-2019-12402 | HIGH | 7.5 | 16.2% | Aug 30, 2019 | The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop w... |
| CVE-2019-13608 | HIGH | 7.5 | 28.0% | Aug 29, 2019 | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE at... |
| CVE-2019-7307 | HIGH | 7 | 0.3% | Aug 29, 2019 | Apport before versions 2.14.1-0ubuntu3.29+esm1, 2.20.1-0ubuntu2.19, 2.20.9-0ubuntu7.7, 2.20.10-0ubuntu27.1, 2.20.11-0ubu... |
| CVE-2019-13408 | HIGH | 7.5 | 1.9% | Aug 29, 2019 | A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download... |
| CVE-2019-11248 | HIGH | 8.2 | 61.1% | Aug 29, 2019 | The debugging endpoint /debug/pprof is exposed over the unauthenticated Kubelet healthz port. The go pprof endpoint is e... |
| CVE-2019-11247 | HIGH | 8.1 | 2.1% | Aug 29, 2019 | The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if ... |
| CVE-2019-11060 | HIGH | 7.5 | 3.0% | Aug 29, 2019 | The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Se... |
| CVE-2019-15752 | HIGH | 7.8 | 29.6% | Aug 28, 2019 | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c... |
| CVE-2019-1965 | HIGH | 7.7 | 1.5% | Aug 28, 2019 | A vulnerability in the Virtual Shell (VSH) session management for Cisco NX-OS Software could allow an authenticated, rem... |
| CVE-2019-1964 | HIGH | 8.6 | 1.9% | Aug 28, 2019 | A vulnerability in the IPv6 traffic processing of Cisco NX-OS Software could allow an unauthenticated, remote attacker t... |
| CVE-2019-1963 | HIGH | 7.7 | 1.6% | Aug 28, 2019 | A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco FXOS Software and Cisco... |
| CVE-2019-1962 | HIGH | 8.6 | 1.9% | Aug 28, 2019 | A vulnerability in the Cisco Fabric Services component of Cisco NX-OS Software could allow an unauthenticated, remote at... |
| CVE-2019-10390 | HIGH | 8.8 | 1.7% | Aug 28, 2019 | A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission... |
| CVE-2019-10384 | HIGH | 8.8 | 1.6% | Aug 28, 2019 | Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session... |
| CVE-2019-15702 | HIGH | 7.5 | 1.4% | Aug 27, 2019 | In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all input... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now