2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12138 | — | — | 0.9% | May 16, 2019 | MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shar... |
| CVE-2019-12137 | — | — | 6.5% | May 16, 2019 | Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substr... |
| CVE-2019-12136 | — | — | 0.6% | May 16, 2019 | There is XSS in BoostIO Boostnote 0.11.15 via a label named mermaid, as demonstrated by a crafted SRC attribute of an IF... |
| CVE-2019-12110 | — | — | 2.6% | May 15, 2019 | An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer derefer... |
| CVE-2019-12109 | — | — | 2.8% | May 15, 2019 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutbo... |
| CVE-2019-12108 | — | — | 2.8% | May 15, 2019 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutbo... |
| CVE-2019-12107 | — | — | 3.0% | May 15, 2019 | The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak infor... |
| CVE-2019-12106 | — | — | 2.8% | May 15, 2019 | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process... |
| CVE-2019-9196 | — | — | 2.1% | May 15, 2019 | The Face authentication component in Aware mobile liveness 2.2.1 sdk 2.2.0 for Knomi allows a Biometrical Liveness authe... |
| CVE-2019-10111 | — | — | 1.0% | May 15, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x befor... |
| CVE-2019-10110 | — | — | 1.2% | May 15, 2019 | An Insecure Permissions issue (issue 1 of 3) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11... |
| CVE-2019-10109 | — | — | 2.0% | May 15, 2019 | An Information Exposure issue (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11... |
| CVE-2019-10108 | — | — | 1.0% | May 15, 2019 | An Incorrect Access Control (issue 1 of 2) was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8... |
| CVE-2019-10640 | — | — | 2.2% | May 15, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x befo... |
| CVE-2019-11224 | — | — | 6.5% | May 15, 2019 | HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection. |
| CVE-2019-1010258 | — | — | 1.8% | May 15, 2019 | nanosvg library nanosvg after commit c1f6e209c16b18b46aa9f45d7e619acf42c29726 is affected by: Buffer Overflow. The impac... |
| CVE-2019-5598 | — | — | 3.3% | May 15, 2019 | In FreeBSD 11.3-PRERELEASE before r345378, 12.0-STABLE before r345377, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RE... |
| CVE-2019-5597 | — | — | 3.6% | May 15, 2019 | In FreeBSD 11.3-PRERELEASE and 12.0-STABLE before r347591, 11.2-RELEASE before 11.2-RELEASE-p10, and 12.0-RELEASE before... |
| CVE-2019-5526 | — | — | 9.0% | May 15, 2019 | VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by t... |
| CVE-2019-12101 | — | — | 1.9% | May 15, 2019 | coap_decode_option in coap.c in LibNyoci 0.07.00rc1 mishandles certain packets with "Uri-Path: (null)" and consequently ... |
| CVE-2019-12099 | — | — | 17.5% | May 14, 2019 | In PHP-Fusion 9.03.00, edit_profile.php allows remote authenticated users to execute arbitrary code because includes/dyn... |
| CVE-2019-11397 | — | — | 5.5% | May 14, 2019 | GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Loca... |
| CVE-2019-0301 | — | — | 1.1% | May 14, 2019 | Under certain conditions, it is possible to request the modification of role or privilege assignments through SAP Identi... |
| CVE-2019-0298 | — | — | 1.3% | May 14, 2019 | SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cros... |
| CVE-2019-0293 | — | — | 1.5% | May 14, 2019 | Read of RFC destination does not always perform necessary authorization checks, resulting in escalation of privileges to... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now