2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5051 | HIGH | 8.8 | 4.0% | Jul 3, 2019 | An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A m... |
| CVE-2019-6631 | HIGH | 7.5 | 2.5% | Jul 3, 2019 | On BIG-IP 11.5.1-11.6.4, iRules performing HTTP header manipulation may cause an interruption to service when processing... |
| CVE-2019-6629 | HIGH | 7.5 | 1.3% | Jul 3, 2019 | On BIG-IP 14.1.0-14.1.0.5, undisclosed SSL traffic to a virtual server configured with a Client SSL profile may cause TM... |
| CVE-2019-13164 | HIGH | 7.8 | 0.5% | Jul 3, 2019 | qemu-bridge-helper.c in QEMU 3.1 and 4.0.0 does not ensure that a network interface name (obtained from bridge.conf or a... |
| CVE-2019-6623 | HIGH | 7.5 | 2.5% | Jul 2, 2019 | On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, undisclosed traffic sent to BIG-IP iSess... |
| CVE-2019-10137 | HIGH | 8.1 | 3.1% | Jul 2, 2019 | A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached clie... |
| CVE-2019-7258 | HIGH | 8.8 | 19.6% | Jul 2, 2019 | Linear eMerge E3-Series devices allow Privilege Escalation. |
| CVE-2019-7254 | HIGH | 7.5 | 82.0% | Jul 2, 2019 | Linear eMerge E3-Series devices allow File Inclusion. |
| CVE-2019-5443 | HIGH | 7.8 | 0.7% | Jul 2, 2019 | A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) tha... |
| CVE-2019-7262 | HIGH | 8.8 | 16.3% | Jul 2, 2019 | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). |
| CVE-2019-7259 | HIGH | 8.8 | 13.2% | Jul 2, 2019 | Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure. |
| CVE-2019-7270 | HIGH | 8.8 | 1.1% | Jul 2, 2019 | Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). |
| CVE-2019-4292 | HIGH | 8.8 | 3.7% | Jul 2, 2019 | IBM Security Guardium 10.5 could allow a remote attacker to upload arbitrary files, which could allow the attacker to ex... |
| CVE-2019-4140 | HIGH | 7.1 | 0.3% | Jul 2, 2019 | IBM Tivoli Storage Manager Server (IBM Spectrum Protect 7.1 and 8.1) could allow a local user to replace existing databa... |
| CVE-2019-4088 | HIGH | 7.8 | 0.5% | Jul 2, 2019 | IBM Spectrum Protect Servers 7.1 and 8.1 and Storage Agents could allow a local attacker to gain elevated privileges on ... |
| CVE-2019-7273 | HIGH | 8.8 | 4.5% | Jul 1, 2019 | Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF). |
| CVE-2019-6642 | HIGH | 8.8 | 1.8% | Jul 1, 2019 | In BIG-IP 15.0.0, 14.0.0-14.1.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.2, and 11.5.2-11.6.4, BIG-IQ 6.0.0-6.1.0 and 5.1.0-5.4... |
| CVE-2019-13135 | HIGH | 8.8 | 3.3% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.... |
| CVE-2019-7670 | HIGH | 7.2 | 18.3% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo... |
| CVE-2019-7669 | HIGH | 8.8 | 31.4% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. Improper validation of file extensions when uploading files could allo... |
| CVE-2019-7666 | HIGH | 8.8 | 14.8% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu... |
| CVE-2019-7281 | HIGH | 8.8 | 0.9% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. An unauthenticated user can send unverified HTTP requests, which may a... |
| CVE-2019-7280 | HIGH | 8.8 | 2.4% | Jul 1, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length and can be exploited by br... |
| CVE-2019-4322 | HIGH | 7.8 | 0.5% | Jul 1, 2019 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 is vulnerable to a buffer ov... |
| CVE-2019-4298 | HIGH | 7.1 | 0.3% | Jul 1, 2019 | IBM Robotic Process Automation with Automation Anywhere 11 uses a high privileged PostgreSQL account for database access... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now