2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2866 | HIGH | 8.2 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2865 | HIGH | 7.5 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2864 | HIGH | 7.5 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2859 | HIGH | 8.8 | 0.5% | Jul 23, 2019 | Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th... |
| CVE-2019-2832 | HIGH | 8.8 | 0.4% | Jul 23, 2019 | Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environ... |
| CVE-2019-2822 | HIGH | 7.5 | 2.8% | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Cluster). Supported ver... |
| CVE-2019-2800 | HIGH | 7.1 | 2.3% | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that... |
| CVE-2019-2792 | HIGH | 7.3 | 1.3% | Jul 23, 2019 | Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter... |
| CVE-2019-14243 | HIGH | 7.5 | 4.3% | Jul 23, 2019 | headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin throu... |
| CVE-2019-9818 | HIGH | 8.3 | 1.0% | Jul 23, 2019 | A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can ... |
| CVE-2019-9811 | HIGH | 8.3 | 2.6% | Jul 23, 2019 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack a... |
| CVE-2019-11723 | HIGH | 7.5 | 0.8% | Jul 23, 2019 | A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the b... |
| CVE-2019-11711 | HIGH | 8.8 | 1.6% | Jul 23, 2019 | When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages o... |
| CVE-2019-11707 | HIGH | 8.8 | 38.0% | Jul 23, 2019 | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow... |
| CVE-2019-11706 | HIGH | 7.5 | 9.7% | Jul 23, 2019 | A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro... |
| CVE-2019-12327 | HIGH | 7.2 | 1.9% | Jul 22, 2019 | Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet.... |
| CVE-2019-1010218 | HIGH | 7.5 | 1.3% | Jul 22, 2019 | Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CW... |
| CVE-2019-12326 | HIGH | 7.2 | 3.0% | Jul 22, 2019 | Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an atta... |
| CVE-2019-12325 | HIGH | 8.8 | 2.0% | Jul 22, 2019 | The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware vers... |
| CVE-2019-12324 | HIGH | 7.2 | 4.3% | Jul 22, 2019 | A command injection (missing input validation) issue in the IP address field for the logging server in the configuration... |
| CVE-2019-4267 | HIGH | 7.8 | 0.4% | Jul 22, 2019 | The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow executio... |
| CVE-2019-14213 | HIGH | 7.5 | 2.1% | Jul 21, 2019 | An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of th... |
| CVE-2019-14211 | HIGH | 7.5 | 1.7% | Jul 21, 2019 | An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validat... |
| CVE-2019-14206 | HIGH | 7.5 | 4.8% | Jul 21, 2019 | An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote a... |
| CVE-2019-14205 | HIGH | 7.5 | 63.4% | Jul 21, 2019 | A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attac... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now