2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9539 | MEDIUM | 6.1 | 0.8% | Jan 3, 2020 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ModalWindowPopup... |
| CVE-2019-9538 | MEDIUM | 6.1 | 0.8% | Jan 3, 2020 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the LDAP cbURL p... |
| CVE-2019-9537 | MEDIUM | 6.1 | 0.8% | Jan 3, 2020 | : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp o... |
| CVE-2019-19959 | HIGH | 7.5 | 3.2% | Jan 3, 2020 | ext/misc/zipfile.c in SQLite 3.30.1 mishandles certain uses of INSERT INTO in situations involving embedded '\0' charact... |
| CVE-2019-11994 | CRITICAL | 9.8 | 7.2% | Jan 3, 2020 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 ... |
| CVE-2019-11993 | HIGH | 7.5 | 1.5% | Jan 3, 2020 | A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 ... |
| CVE-2019-5064 | HIGH | 8.8 | 10.6% | Jan 3, 2020 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, befo... |
| CVE-2019-5063 | HIGH | 8.8 | 20.9% | Jan 3, 2020 | An exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV 4.1.0... |
| CVE-2019-19310 | MEDIUM | 4.9 | 0.9% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 9.0 and later through 12.5 allows Information Disclosure. |
| CVE-2019-19309 | MEDIUM | 4.3 | 0.8% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 8.90 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19263 | MEDIUM | 4.3 | 0.6% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions. |
| CVE-2019-19262 | MEDIUM | 4.3 | 0.8% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions. |
| CVE-2019-19261 | HIGH | 8.8 | 1.0% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF. |
| CVE-2019-19260 | MEDIUM | 5.4 | 0.7% | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 2 of 2). |
| CVE-2019-19259 | MEDIUM | 4.3 | 0.6% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 11.3 and later through 12.5 allows an Insecure Direct Object Reference (IDOR). |
| CVE-2019-19258 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 10.8 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19257 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE) through 12.5 has Incorrect Access Control (issue 1 of 2). |
| CVE-2019-19256 | MEDIUM | 5.3 | 0.9% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 12.2 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19255 | MEDIUM | 4.3 | 0.8% | Jan 3, 2020 | GitLab Enterprise Edition (EE) 12.3 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19311 | MEDIUM | 5.4 | 0.7% | Jan 3, 2020 | GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields. |
| CVE-2019-19254 | MEDIUM | 5.3 | 1.1% | Jan 3, 2020 | GitLab Community Edition (CE) and Enterprise Edition (EE). 9.6 and later through 12.5 has Incorrect Access Control. |
| CVE-2019-19088 | CRITICAL | 9.8 | 1.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) 11.3 through 12.4.2 allows Directory Traversal. |
| CVE-2019-19087 | MEDIUM | 4.3 | 0.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2). |
| CVE-2019-19086 | MEDIUM | 4.3 | 0.7% | Jan 3, 2020 | Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). |
| CVE-2019-5304 | HIGH | 7.5 | 1.0% | Jan 3, 2020 | Some Huawei products have a buffer error vulnerability. An unauthenticated, remote attacker could send specific MPLS Ech... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now