2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19680HIGH8.8A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P...
CVE-2019-20148MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 8.13 through 12.6.1. It has Incorre...
CVE-2019-20147MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 9.1 through 12.6.1. It has Incorrec...
CVE-2019-20146MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.0 through 12.6. It allows Uncont...
CVE-2019-20145MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 11.4 through 12.6.1. It has Incorre...
CVE-2019-19728HIGH7.5SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
CVE-2019-19727MEDIUM5.5SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
CVE-2019-20212MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste...
CVE-2019-20211MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persiste...
CVE-2019-20210MEDIUM6.1The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflecte...
CVE-2019-20209HIGH7.5The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure ...
CVE-2019-19891MEDIUM5.9An encryption key vulnerability on Mitel SIP-DECT wireless devices 8.0 and 8.1 could allow an attacker to launch a man-i...
CVE-2019-18894HIGH7.8In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast...
CVE-2019-18893MEDIUM6.1XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.7...
CVE-2019-19547MEDIUM6.1Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issu...
CVE-2019-20377MEDIUM6.1TopList before 2019-09-03 allows XSS via a title.
CVE-2019-20379MEDIUM6.1ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter.
CVE-2019-20378MEDIUM6.1ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter.
CVE-2019-19475HIGH8.8An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-i...
CVE-2019-13767HIGH8.8Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the ...
CVE-2019-18588MEDIUM5.4Dell EMC Unisphere for PowerMax versions prior to 9.1.0.9, Dell EMC Unisphere for PowerMax versions prior to 9.0.2.16, a...
CVE-2019-19819MEDIUM5.5The JBIG2Globals library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDes...
CVE-2019-19817MEDIUM5.5The JBIG2Decode library in npdf.dll in Nitro Free PDF Reader 12.0.0.112 has a CAPPDAnnotHandlerUtils::PDAnnotHandlerDest...
CVE-2019-18194HIGH7.8TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio...
CVE-2019-14306HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now