2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19441MEDIUM6.5HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An at...
CVE-2019-20330CRITICAL9.8FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
CVE-2019-20329HIGH8.1OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000.
CVE-2019-10205MEDIUM6.3A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database...
CVE-2019-20225MEDIUM6.1MyBB before 1.8.22 allows an open redirect on login.
CVE-2019-20219HIGH8.8ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c.
CVE-2019-14864MEDIUM6.5Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the...
CVE-2019-14863MEDIUM6.1There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web applic...
CVE-2019-14862MEDIUM6.1There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application,...
CVE-2019-14859CRITICAL9.1A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used D...
CVE-2019-10775HIGH7.5ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.
CVE-2019-10158CRITICAL9.8A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protecti...
CVE-2019-20223MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a...
CVE-2019-20222MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page a...
CVE-2019-20221MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload i...
CVE-2019-20220MEDIUM6.1In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected b...
CVE-2019-20218HIGH7.5selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error.
CVE-2019-20213HIGH7.5D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v...
CVE-2019-20208MEDIUM5.5dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.
CVE-2019-20205HIGH8.8libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
CVE-2019-20204MEDIUM5.4The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn...
CVE-2019-20203MEDIUM5.3The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s...
CVE-2019-20202MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block ...
CVE-2019-20201MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an ...
CVE-2019-20200MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, perfo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now