2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7614 | MEDIUM | 5.9 | 1.0% | Jul 30, 2019 | A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a reque... |
| CVE-2019-5460 | MEDIUM | 5.5 | 2.5% | Jul 30, 2019 | Double Free in VLC versions <= 3.0.6 leads to a crash. |
| CVE-2019-5458 | MEDIUM | 5.4 | 0.7% | Jul 30, 2019 | Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server... |
| CVE-2019-5457 | MEDIUM | 5.4 | 0.7% | Jul 30, 2019 | Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server ... |
| CVE-2019-5455 | MEDIUM | 6.8 | 0.5% | Jul 30, 2019 | Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process. |
| CVE-2019-5453 | MEDIUM | 6.1 | 0.5% | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f... |
| CVE-2019-5451 | MEDIUM | 4.6 | 0.4% | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly op... |
| CVE-2019-5450 | MEDIUM | 6.8 | 0.5% | Jul 30, 2019 | Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style th... |
| CVE-2019-5449 | MEDIUM | 4.3 | 0.9% | Jul 30, 2019 | A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or mo... |
| CVE-2019-14383 | MEDIUM | 6.5 | 1.3% | Jul 30, 2019 | J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
| CVE-2019-14382 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
| CVE-2019-14380 | MEDIUM | 6.5 | 0.9% | Jul 30, 2019 | libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. |
| CVE-2019-10130 | MEDIUM | 4.3 | 1.1% | Jul 30, 2019 | A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excl... |
| CVE-2019-10129 | MEDIUM | 6.5 | 1.6% | Jul 30, 2019 | A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned tab... |
| CVE-2019-4285 | MEDIUM | 5.4 | 1.1% | Jul 30, 2019 | IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of t... |
| CVE-2019-14444 | MEDIUM | 5.5 | 1.5% | Jul 30, 2019 | apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a writ... |
| CVE-2019-14443 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote at... |
| CVE-2019-14442 | MEDIUM | 6.5 | 1.0% | Jul 30, 2019 | In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang... |
| CVE-2019-14441 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (applica... |
| CVE-2019-14415 | MEDIUM | 4.8 | 1.1% | Jul 29, 2019 | An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vul... |
| CVE-2019-1020017 | MEDIUM | 5.3 | 0.9% | Jul 29, 2019 | Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP. |
| CVE-2019-1020014 | MEDIUM | 5.5 | 0.4% | Jul 29, 2019 | docker-credential-helpers before 0.6.3 has a double free in the List functions. |
| CVE-2019-14372 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c. |
| CVE-2019-14370 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result i... |
| CVE-2019-14369 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-b... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now