2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-11276MEDIUM5.4Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5...
CVE-2019-15145MEDIUM5.5DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by c...
CVE-2019-15144MEDIUM5.5In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-se...
CVE-2019-15143MEDIUM5.5In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustio...
CVE-2019-15142MEDIUM5.5In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application...
CVE-2019-15141MEDIUM6.5WriteTIFFImage in coders/tiff.c in ImageMagick 7.0.8-43 Q16 allows attackers to cause a denial-of-service (application c...
CVE-2019-15133MEDIUM6.5In GIFLIB before 2019-02-16, a malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp ...
CVE-2019-15132MEDIUM5.3Zabbix through 4.4.0alpha1 allows User Enumeration. With login requests, it is possible to enumerate application usernam...
CVE-2019-15116MEDIUM6.1The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
CVE-2019-15120MEDIUM5.4The Kunena extension before 5.1.14 for Joomla! allows XSS via BBCode.
CVE-2019-15119MEDIUM5.5lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, lead...
CVE-2019-15118MEDIUM5.5check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack ex...
CVE-2019-15108MEDIUM4.8An issue was discovered in WSO2 API Manager 2.6.0 before WSO2-CARBON-PATCH-4.4.0-4457. There is XSS via a crafted filena...
CVE-2019-15098MEDIUM4.6drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through 5.2.9 has a NULL pointer dereference via an incomplete...
CVE-2019-15090MEDIUM6.7An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux kernel before 5.1.12. In the qedi_dbg_* family of f...
CVE-2019-13377MEDIUM5.9The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel atta...
CVE-2019-13223MEDIUM5.5A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a deni...
CVE-2019-13219MEDIUM5.5A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a den...
CVE-2019-13218MEDIUM5.5Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of ...
CVE-2019-10140MEDIUM5.5A vulnerability was found in Linux kernel's, versions up to 3.10, implementation of overlayfs. An attacker with local ac...
CVE-2019-14786MEDIUM6.5The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.p...
CVE-2019-3418MEDIUM5.4All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by cross-site scripting vulnerability (XSS). Due t...
CVE-2019-15081MEDIUM4.8OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe...
CVE-2019-1228MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker...
CVE-2019-1227MEDIUM5.5An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now