2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3837 | MEDIUM | 6.1 | 0.2% | Apr 11, 2019 | It was found that the net_dma code in tcp_recvmsg() in the 2.6.32 kernel as shipped in RHEL6 is thread-unsafe. So an unp... |
| CVE-2019-1003050 | MEDIUM | 5.4 | 1.3% | Apr 10, 2019 | The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and J... |
| CVE-2019-3612 | MEDIUM | 4.4 | 0.2% | Apr 10, 2019 | Information Disclosure vulnerability in McAfee DXL Platform and TIE Server in DXL prior to 5.0.1 HF2 and TIE prior to 2.... |
| CVE-2019-0042 | MEDIUM | 4.2 | 0.3% | Apr 10, 2019 | Juniper Identity Management Service (JIMS) for Windows versions prior to 1.1.4 may send an incorrect message to associat... |
| CVE-2019-0038 | MEDIUM | 6.5 | 0.7% | Apr 10, 2019 | Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services gateway may create a denial ... |
| CVE-2019-0035 | MEDIUM | 6.8 | 0.4% | Apr 10, 2019 | When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the roo... |
| CVE-2019-5426 | MEDIUM | 4.8 | 0.8% | Apr 10, 2019 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an unauthenticated user can use the "local port forwarding" and "dyn... |
| CVE-2019-6154 | MEDIUM | 5.3 | 0.9% | Apr 10, 2019 | A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a... |
| CVE-2019-11065 | MEDIUM | 5.9 | 1.4% | Apr 10, 2019 | Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or Coff... |
| CVE-2019-8456 | MEDIUM | 5.9 | 20.4% | Apr 9, 2019 | Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the in... |
| CVE-2019-0876 | MEDIUM | 5.5 | 1.6% | Apr 9, 2019 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo... |
| CVE-2019-0858 | MEDIUM | 6.1 | 2.1% | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ... |
| CVE-2019-0831 | MEDIUM | 5.4 | 1.6% | Apr 9, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-0830 | MEDIUM | 5.4 | 1.6% | Apr 9, 2019 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall... |
| CVE-2019-0817 | MEDIUM | 5.4 | 2.3% | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ... |
| CVE-2019-9133 | MEDIUM | 5.5 | 1.7% | Apr 9, 2019 | When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly... |
| CVE-2019-5615 | MEDIUM | 6.5 | 0.8% | Apr 9, 2019 | Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Globa... |
| CVE-2019-3893 | MEDIUM | 4.9 | 1.9% | Apr 9, 2019 | In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to th... |
| CVE-2019-3887 | MEDIUM | 5.6 | 0.4% | Apr 9, 2019 | A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtua... |
| CVE-2019-3880 | MEDIUM | 5.4 | 3.4% | Apr 9, 2019 | A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivilege... |
| CVE-2019-3870 | MEDIUM | 6.1 | 0.6% | Apr 9, 2019 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation... |
| CVE-2019-3795 | MEDIUM | 5.3 | 1.9% | Apr 9, 2019 | Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure rand... |
| CVE-2019-0757 | MEDIUM | 6.5 | 2.7% | Apr 9, 2019 | A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attack... |
| CVE-2019-0703 | MEDIUM | 6.5 | 9.6% | Apr 9, 2019 | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win... |
| CVE-2019-11026 | MEDIUM | 6.5 | 1.8% | Apr 8, 2019 | FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error funct... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now