2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11405 | HIGH | 8.1 | 1.2% | Apr 22, 2019 | OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle... |
| CVE-2019-11404 | HIGH | 8.1 | 1.1% | Apr 22, 2019 | arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP in... |
| CVE-2019-11354 | HIGH | 7.8 | 23.1% | Apr 19, 2019 | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori... |
| CVE-2019-4055 | HIGH | 7.5 | 2.5% | Apr 19, 2019 | IBM MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, and 9.1.0.0 through 9.1.1 is vulnerable to a denial of service... |
| CVE-2019-10245 | HIGH | 7.5 | 2.5% | Apr 19, 2019 | In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past th... |
| CVE-2019-11338 | HIGH | 8.8 | 2.4% | Apr 19, 2019 | libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attacke... |
| CVE-2019-3719 | HIGH | 8 | 17.6% | Apr 18, 2019 | Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated a... |
| CVE-2019-3718 | HIGH | 8.8 | 0.7% | Apr 18, 2019 | Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthentic... |
| CVE-2019-3398 | HIGH | 8.8 | 97.2% | Apr 18, 2019 | Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at... |
| CVE-2019-10303 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | Jenkins Azure PublisherSettings Credentials Plugin 1.2 and earlier stored credentials unencrypted in the credentials.xml... |
| CVE-2019-10302 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins m... |
| CVE-2019-10301 | HIGH | 8.8 | 1.4% | Apr 18, 2019 | A missing permission check in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doTestConnection fo... |
| CVE-2019-1840 | HIGH | 8.6 | 2.4% | Apr 18, 2019 | A vulnerability in the DHCPv6 input packet processor of Cisco Prime Network Registrar could allow an unauthenticated, re... |
| CVE-2019-1834 | HIGH | 7.4 | 0.6% | Apr 18, 2019 | A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthentic... |
| CVE-2019-1797 | HIGH | 8.8 | 0.7% | Apr 18, 2019 | A vulnerability in the web-based management interface of Cisco Wireless LAN Controller (WLC) Software could allow an una... |
| CVE-2019-1718 | HIGH | 7.5 | 2.5% | Apr 17, 2019 | A vulnerability in the web interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote atta... |
| CVE-2019-1686 | HIGH | 8.6 | 1.6% | Apr 17, 2019 | A vulnerability in the TCP flags inspection feature for access control lists (ACLs) on Cisco ASR 9000 Series Aggregation... |
| CVE-2019-1654 | HIGH | 7.8 | 0.4% | Apr 17, 2019 | A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running ... |
| CVE-2019-8455 | HIGH | 7.1 | 0.4% | Apr 17, 2019 | A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its per... |
| CVE-2019-10953 | HIGH | 7.5 | 3.7% | Apr 17, 2019 | ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers, multiple versions. Researchers... |
| CVE-2019-10951 | HIGH | 7.8 | 2.9% | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple heap-based buffer overflow... |
| CVE-2019-10947 | HIGH | 7.8 | 3.7% | Apr 17, 2019 | Delta Industrial Automation CNCSoft, CNCSoft ScreenEditor Version 1.00.88 and prior. Multiple stack-based buffer overflo... |
| CVE-2019-9499 | HIGH | 8.1 | 2.4% | Apr 17, 2019 | The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validati... |
| CVE-2019-9498 | HIGH | 8.1 | 2.4% | Apr 17, 2019 | The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on... |
| CVE-2019-6575 | HIGH | 7.5 | 1.6% | Apr 17, 2019 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now