2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19441 | MEDIUM | 6.5 | 0.3% | Jan 3, 2020 | HUAWEI P30 smart phones with versions earlier than 10.0.0.166(C00E66R1P11) have an information leak vulnerability. An at... |
| CVE-2019-20330 | CRITICAL | 9.8 | 8.6% | Jan 3, 2020 | FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking. |
| CVE-2019-20329 | HIGH | 8.1 | 0.6% | Jan 3, 2020 | OpenLambda 2019-09-10 allows DNS rebinding attacks against the OL server for the REST API on TCP port 5000. |
| CVE-2019-10205 | MEDIUM | 6.3 | 0.3% | Jan 2, 2020 | A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database... |
| CVE-2019-20225 | MEDIUM | 6.1 | 0.6% | Jan 2, 2020 | MyBB before 1.8.22 allows an open redirect on login. |
| CVE-2019-20219 | HIGH | 8.8 | 1.3% | Jan 2, 2020 | ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. |
| CVE-2019-14864 | MEDIUM | 6.5 | 1.9% | Jan 2, 2020 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the... |
| CVE-2019-14863 | MEDIUM | 6.1 | 1.4% | Jan 2, 2020 | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web applic... |
| CVE-2019-14862 | MEDIUM | 6.1 | 2.0% | Jan 2, 2020 | There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application,... |
| CVE-2019-14859 | CRITICAL | 9.1 | 1.6% | Jan 2, 2020 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used D... |
| CVE-2019-10775 | HIGH | 7.5 | 1.3% | Jan 2, 2020 | ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application. |
| CVE-2019-10158 | CRITICAL | 9.8 | 2.0% | Jan 2, 2020 | A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protecti... |
| CVE-2019-20223 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a... |
| CVE-2019-20222 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page a... |
| CVE-2019-20221 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload i... |
| CVE-2019-20220 | MEDIUM | 6.1 | 0.7% | Jan 2, 2020 | In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected b... |
| CVE-2019-20218 | HIGH | 7.5 | 3.6% | Jan 2, 2020 | selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error. |
| CVE-2019-20213 | HIGH | 7.5 | 1.9% | Jan 2, 2020 | D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a v... |
| CVE-2019-20208 | MEDIUM | 5.5 | 1.5% | Jan 2, 2020 | dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow. |
| CVE-2019-20205 | HIGH | 8.8 | 1.0% | Jan 2, 2020 | libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c. |
| CVE-2019-20204 | MEDIUM | 5.4 | 3.4% | Jan 2, 2020 | The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the beginn... |
| CVE-2019-20203 | MEDIUM | 5.3 | 2.1% | Jan 2, 2020 | The Authorized Addresses feature in the Postie plugin 1.9.40 for WordPress allows remote attackers to publish posts by s... |
| CVE-2019-20202 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_char_content() tries to use realloc on a block ... |
| CVE-2019-20201 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML entities, leading to an ... |
| CVE-2019-20200 | MEDIUM | 6.5 | 1.2% | Dec 31, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing crafted a XML file, perfo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now