2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-7614MEDIUM5.9A race condition flaw was found in the response headers Elasticsearch versions before 7.2.1 and 6.8.2 returns to a reque...
CVE-2019-5460MEDIUM5.5Double Free in VLC versions <= 3.0.6 leads to a crash.
CVE-2019-5458MEDIUM5.4Cross-site scripting (XSS) vulnerability in http-file-server (all versions) allows an attacker with access to the server...
CVE-2019-5457MEDIUM5.4Cross-site scripting (XSS) vulnerability in min-http-server (all versions) allows an attacker with access to the server ...
CVE-2019-5455MEDIUM6.8Bypassing lock protection exists in Nextcloud Android app 3.6.0 when creating a multi-account and aborting the process.
CVE-2019-5453MEDIUM6.1Bypass lock protection in the Nextcloud Android app prior to version 3.3.0 allowed access to files when being prompted f...
CVE-2019-5451MEDIUM4.6Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly op...
CVE-2019-5450MEDIUM6.8Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style th...
CVE-2019-5449MEDIUM4.3A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or mo...
CVE-2019-14383MEDIUM6.5J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
CVE-2019-14382MEDIUM6.5DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs.
CVE-2019-14380MEDIUM6.5libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files.
CVE-2019-10130MEDIUM4.3A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excl...
CVE-2019-10129MEDIUM6.5A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned tab...
CVE-2019-4285MEDIUM5.4IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of t...
CVE-2019-14444MEDIUM5.5apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a writ...
CVE-2019-14443MEDIUM6.5An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote at...
CVE-2019-14442MEDIUM6.5In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang...
CVE-2019-14441MEDIUM6.5An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (applica...
CVE-2019-14415MEDIUM4.8An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. A persistent cross-site scripting (XSS) vul...
CVE-2019-1020017MEDIUM5.3Discourse before 2.3.0 and 2.4.x before 2.4.0.beta3 lacks a confirmation screen when logging in via a user-api OTP.
CVE-2019-1020014MEDIUM5.5docker-credential-helpers before 0.6.3 has a double free in the List functions.
CVE-2019-14372MEDIUM6.5In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c.
CVE-2019-14370MEDIUM6.5In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result i...
CVE-2019-14369MEDIUM6.5Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-b...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now