2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11815 | HIGH | 8.1 | 4.5% | May 8, 2019 | An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race conditio... |
| CVE-2019-4208 | HIGH | 7.1 | 1.9% | May 7, 2019 | IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when pro... |
| CVE-2019-10869 | HIGH | 8.1 | 13.0% | May 7, 2019 | Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploa... |
| CVE-2019-11811 | HIGH | 7 | 0.5% | May 7, 2019 | An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/... |
| CVE-2019-11810 | HIGH | 7.5 | 5.8% | May 7, 2019 | An issue was discovered in the Linux kernel before 5.0.7. A NULL pointer dereference can occur when megasas_create_frame... |
| CVE-2019-5432 | HIGH | 7.5 | 1.6% | May 6, 2019 | A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0... |
| CVE-2019-3565 | HIGH | 7.5 | 2.8% | May 6, 2019 | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers o... |
| CVE-2019-3564 | HIGH | 7.5 | 2.0% | May 6, 2019 | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a resul... |
| CVE-2019-3559 | HIGH | 7.5 | 2.0% | May 6, 2019 | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a res... |
| CVE-2019-3558 | HIGH | 7.5 | 2.0% | May 6, 2019 | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a r... |
| CVE-2019-3552 | HIGH | 7.5 | 2.0% | May 6, 2019 | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown ty... |
| CVE-2019-10249 | HIGH | 8.1 | 0.6% | May 6, 2019 | All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artif... |
| CVE-2019-6619 | HIGH | 7.5 | 1.8% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when... |
| CVE-2019-6616 | HIGH | 7.2 | 1.6% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with... |
| CVE-2019-6158 | HIGH | 8.7 | 1.5% | May 3, 2019 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being writt... |
| CVE-2019-3894 | HIGH | 8.8 | 1.5% | May 3, 2019 | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a Securi... |
| CVE-2019-6612 | HIGH | 7.5 | 1.8% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, DNS query TCP connections... |
| CVE-2019-6611 | HIGH | 7.5 | 1.8% | May 3, 2019 | When BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8 are processing certain r... |
| CVE-2019-1859 | HIGH | 7.2 | 0.9% | May 3, 2019 | A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow a... |
| CVE-2019-1836 | HIGH | 7.1 | 0.4% | May 3, 2019 | A vulnerability in the system shell for Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (A... |
| CVE-2019-1817 | HIGH | 7.5 | 1.8% | May 3, 2019 | A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliance could allow an... |
| CVE-2019-1816 | HIGH | 7.8 | 0.6% | May 3, 2019 | A vulnerability in the log subscription subsystem of the Cisco Web Security Appliance (WSA) could allow an authenticated... |
| CVE-2019-1807 | HIGH | 7.6 | 1.5% | May 3, 2019 | A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an au... |
| CVE-2019-1724 | HIGH | 8.8 | 1.5% | May 3, 2019 | A vulnerability in the session management functionality of the web-based interface for Cisco Small Business RV320 and RV... |
| CVE-2019-1715 | HIGH | 7.5 | 1.7% | May 3, 2019 | A vulnerability in the Deterministic Random Bit Generator (DRBG), also known as Pseudorandom Number Generator (PRNG), us... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now