2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11763 | MEDIUM | 6.1 | 1.0% | Jan 8, 2020 | Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entit... |
| CVE-2019-11762 | MEDIUM | 6.1 | 0.6% | Jan 8, 2020 | If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call ar... |
| CVE-2019-11761 | MEDIUM | 5.4 | 0.8% | Jan 8, 2020 | By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in... |
| CVE-2019-11760 | HIGH | 8.8 | 1.4% | Jan 8, 2020 | A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploit... |
| CVE-2019-11759 | HIGH | 8.8 | 1.8% | Jan 8, 2020 | An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This co... |
| CVE-2019-11758 | HIGH | 8.8 | 1.3% | Jan 8, 2020 | Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installe... |
| CVE-2019-11757 | HIGH | 8.8 | 1.3% | Jan 8, 2020 | When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequent... |
| CVE-2019-11756 | HIGH | 8.8 | 1.5% | Jan 8, 2020 | Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of... |
| CVE-2019-11745 | HIGH | 8.8 | 3.0% | Jan 8, 2020 | When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a sm... |
| CVE-2019-19495 | CRITICAL | 9.8 | 4.3% | Jan 8, 2020 | The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to... |
| CVE-2019-5082 | CRITICAL | 9.8 | 3.3% | Jan 8, 2020 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 ... |
| CVE-2019-20367 | CRITICAL | 9.1 | 2.8% | Jan 8, 2020 | nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (s... |
| CVE-2019-20366 | MEDIUM | 6.1 | 1.3% | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents. |
| CVE-2019-20365 | MEDIUM | 6.1 | 1.2% | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page. |
| CVE-2019-20364 | MEDIUM | 6.1 | 1.2% | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp. |
| CVE-2019-20363 | MEDIUM | 6.1 | 1.4% | Jan 8, 2020 | An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents. |
| CVE-2019-19544 | HIGH | 7.8 | 0.4% | Jan 8, 2020 | CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows... |
| CVE-2019-10777 | CRITICAL | 9.8 | 1.6% | Jan 8, 2020 | In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within th... |
| CVE-2019-5188 | MEDIUM | 6.7 | 1.0% | Jan 8, 2020 | A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially c... |
| CVE-2019-19518 | CRITICAL | 9.8 | 2.8% | Jan 8, 2020 | CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server ... |
| CVE-2019-17076 | CRITICAL | 9.8 | 2.5% | Jan 8, 2020 | An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in ... |
| CVE-2019-10778 | CRITICAL | 9.8 | 3.5% | Jan 8, 2020 | devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the ex... |
| CVE-2019-20362 | HIGH | 7.8 | 0.7% | Jan 8, 2020 | In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of ... |
| CVE-2019-14820 | MEDIUM | 4.3 | 0.7% | Jan 8, 2020 | It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterCons... |
| CVE-2019-20361 | CRITICAL | 9.8 | 85.1% | Jan 8, 2020 | There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now