2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10320 | — | — | 1.0% | May 21, 2019 | Jenkins Credentials Plugin 2.1.18 and earlier allowed users with permission to create or update credentials to confirm t... |
| CVE-2019-10078 | — | — | 4.9% | May 20, 2019 | A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, whic... |
| CVE-2019-10077 | — | — | 4.7% | May 20, 2019 | A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could ... |
| CVE-2019-10076 | — | — | 4.7% | May 20, 2019 | A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which ... |
| CVE-2019-12241 | — | — | 2.3% | May 20, 2019 | The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-ca... |
| CVE-2019-12240 | — | — | 2.4% | May 20, 2019 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. |
| CVE-2019-12222 | — | — | 1.9% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the func... |
| CVE-2019-12220 | — | — | 1.9% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12219 | — | — | 2.0% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12218 | — | — | 2.0% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12217 | — | — | 2.3% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12215 | — | — | 1.2% | May 20, 2019 | A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to disc... |
| CVE-2019-12214 | — | — | 1.5% | May 20, 2019 | In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j... |
| CVE-2019-12212 | — | — | 1.9% | May 20, 2019 | When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due ... |
| CVE-2019-12208 | — | — | 1.7% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c. |
| CVE-2019-12207 | — | — | 1.8% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. |
| CVE-2019-12206 | — | — | 2.0% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c. |
| CVE-2019-11809 | — | — | 0.8% | May 20, 2019 | An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data,... |
| CVE-2019-12198 | — | — | 1.3% | May 20, 2019 | In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header. |
| CVE-2019-12185 | — | — | 18.1% | May 20, 2019 | eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may ... |
| CVE-2019-12184 | — | — | 0.7% | May 19, 2019 | There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence... |
| CVE-2019-12173 | — | — | 3.8% | May 18, 2019 | MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A... |
| CVE-2019-12172 | — | — | 1.8% | May 17, 2019 | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an ARE... |
| CVE-2019-12170 | — | — | 8.7% | May 17, 2019 | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) componen... |
| CVE-2019-12168 | — | — | 5.0% | May 17, 2019 | Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administrati... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now