2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-14465HIGH7.8fmt_mtm_load_song in fmt/mtm.c in Schism Tracker 20190722 has a heap-based buffer overflow.
CVE-2019-10185HIGH8.6It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extrac...
CVE-2019-10181HIGH8.1It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file wit...
CVE-2019-10186HIGH8.8A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. A sesskey (CSRF) token was not being utilised by the XML...
CVE-2019-10182HIGH8.2It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files....
CVE-2019-14459HIGH7.5nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c ...
CVE-2019-1901HIGH8.8A vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco Nexus 9000 Series Application Centric Inf...
CVE-2019-5060HIGH8.8An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially ...
CVE-2019-5059HIGH8.8An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-5058HIGH8.8An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-5057HIGH8.8An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A speci...
CVE-2019-4165HIGH7.5IBM StoreIQ 7.6.0.0. through 7.6.0.18 could allow a remote attacker to cause a denial of service attack using repeated r...
CVE-2019-10356HIGH8.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method poin...
CVE-2019-10355HIGH8.8A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts ...
CVE-2019-10162HIGH7.5A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized use...
CVE-2019-10161HIGH7.8It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSave...
CVE-2019-10152HIGH7.2A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside ...
CVE-2019-7615HIGH7.4A TLS certificate validation flaw was found in Elastic APM agent for Ruby versions before 2.9.0. When specifying a trust...
CVE-2019-5459HIGH7.1An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
CVE-2019-5456HIGH8.1SMTP MITM refers to a malicious actor setting up an SMTP proxy server between the UniFi Controller version <= 5.10.21 an...
CVE-2019-5448HIGH8.1Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypte...
CVE-2019-10142HIGH7.1A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excludi...
CVE-2019-10141HIGH8.3A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A S...
CVE-2019-10138HIGH8.8A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform...
CVE-2019-4456HIGH7.1IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XX...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now