2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11879 | — | — | 0.5% | May 10, 2019 | The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a... |
| CVE-2019-11082 | — | — | 1.9% | May 10, 2019 | core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Travers... |
| CVE-2019-11878 | — | — | 0.9% | May 10, 2019 | An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same... |
| CVE-2019-11871 | — | — | 0.9% | May 10, 2019 | The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins. |
| CVE-2019-11870 | — | — | 1.3% | May 9, 2019 | Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Pr... |
| CVE-2019-11869 | — | — | 5.3% | May 9, 2019 | The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that ... |
| CVE-2019-7652 | — | — | 5.2% | May 9, 2019 | TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the ... |
| CVE-2019-11563 | — | — | — | May 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-1568 | — | — | 0.9% | May 9, 2019 | Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated atta... |
| CVE-2019-11842 | — | — | 1.8% | May 9, 2019 | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandle... |
| CVE-2019-7181 | — | — | 9.8% | May 9, 2019 | Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr... |
| CVE-2019-9847 | — | — | 1.0% | May 9, 2019 | A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks poin... |
| CVE-2019-11839 | — | — | 1.6% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to nj... |
| CVE-2019-11838 | — | — | 1.6% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to ... |
| CVE-2019-11837 | — | — | 1.4% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related t... |
| CVE-2019-11353 | — | — | 3.1% | May 9, 2019 | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in p... |
| CVE-2019-0226 | — | — | 1.8% | May 9, 2019 | Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directo... |
| CVE-2019-11836 | — | — | 0.3% | May 9, 2019 | The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persi... |
| CVE-2019-11832 | — | — | 3.9% | May 9, 2019 | TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the app... |
| CVE-2019-11830 | — | — | 2.7% | May 9, 2019 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1... |
| CVE-2019-7442 | — | — | 40.0% | May 8, 2019 | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault... |
| CVE-2019-9698 | — | — | 0.3% | May 8, 2019 | Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulne... |
| CVE-2019-8285 | — | — | 4.4% | May 8, 2019 | Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentiall... |
| CVE-2019-11458 | — | — | 2.1% | May 8, 2019 | An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can ... |
| CVE-2019-11406 | — | — | 0.9% | May 8, 2019 | Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now