2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3561 | — | — | 1.7% | Apr 29, 2019 | Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects a... |
| CVE-2019-3493 | — | — | 1.8% | Apr 29, 2019 | A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.... |
| CVE-2019-11598 | — | — | 4.1% | Apr 29, 2019 | In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which... |
| CVE-2019-11597 | — | — | 3.7% | Apr 29, 2019 | In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi... |
| CVE-2019-11596 | — | — | 3.0% | Apr 29, 2019 | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This cau... |
| CVE-2019-11595 | — | — | 2.4% | Apr 29, 2019 | In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s... |
| CVE-2019-11594 | — | — | 2.4% | Apr 29, 2019 | In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-si... |
| CVE-2019-11593 | — | — | 2.5% | Apr 29, 2019 | In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a clien... |
| CVE-2019-5492 | — | — | 1.5% | Apr 29, 2019 | Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthentica... |
| CVE-2019-11592 | — | — | 0.8% | Apr 29, 2019 | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscat... |
| CVE-2019-11590 | — | — | 1.2% | Apr 29, 2019 | The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, wi... |
| CVE-2019-11577 | — | — | 53.1% | Apr 28, 2019 | dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses. |
| CVE-2019-11576 | — | — | 1.7% | Apr 28, 2019 | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, t... |
| CVE-2019-11568 | — | — | 1.4% | Apr 27, 2019 | An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/na... |
| CVE-2019-11567 | — | — | 1.3% | Apr 27, 2019 | An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an a... |
| CVE-2019-11565 | — | — | 2.8% | Apr 27, 2019 | Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter. |
| CVE-2019-11555 | — | — | 3.3% | Apr 26, 2019 | The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate... |
| CVE-2019-11533 | — | — | 1.2% | Apr 26, 2019 | Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web scr... |
| CVE-2019-11492 | — | — | 1.1% | Apr 26, 2019 | ProjectSend before r1070 writes user passwords to the server logs. |
| CVE-2019-6689 | — | — | 0.8% | Apr 26, 2019 | An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automat... |
| CVE-2019-11220 | — | — | 1.2% | Apr 26, 2019 | An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device... |
| CVE-2019-11219 | — | — | 1.8% | Apr 26, 2019 | The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from... |
| CVE-2019-9813 | — | — | 7.4% | Apr 26, 2019 | Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi... |
| CVE-2019-9809 | — | — | 1.6% | Apr 26, 2019 | If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert me... |
| CVE-2019-9808 | — | — | 0.4% | Apr 26, 2019 | If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now