2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17558 | HIGH | 7.5 | 98.6% | Dec 30, 2019 | Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V... |
| CVE-2019-10774 | CRITICAL | 9.8 | 4.6% | Dec 30, 2019 | php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arb... |
| CVE-2019-4655 | MEDIUM | 4.3 | 1.2% | Dec 30, 2019 | IBM MQ 9.1.0.0, 9.1.0.1, 9.1.0.2, 9.1.0.3, 9.1.1, 9.1.2, and 9.1.3 is vulnerable to a denial of service attack that woul... |
| CVE-2019-4623 | MEDIUM | 5.4 | 0.7% | Dec 30, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4343 | MEDIUM | 6.5 | 1.5% | Dec 30, 2019 | IBM Cognos Analytics 11.0 and 11.1 allows overly permissive cross-origin resource sharing which could allow an attacker ... |
| CVE-2019-4335 | MEDIUM | 5.5 | 0.3% | Dec 30, 2019 | IBM Watson Studio Local 1.2.3 stores key files in the user's home directory which could be obtained by another local use... |
| CVE-2019-20139 | MEDIUM | 5.4 | 26.1% | Dec 30, 2019 | In Nagios XI 5.6.9, XSS exists via the nocscreenapi.php host, hostgroup, or servicegroup parameter, or the schedulerepor... |
| CVE-2019-16535 | CRITICAL | 9.8 | 1.7% | Dec 30, 2019 | In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can... |
| CVE-2019-15024 | MEDIUM | 6.5 | 0.9% | Dec 30, 2019 | In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a cust... |
| CVE-2019-20138 | HIGH | 7.5 | 0.8% | Dec 30, 2019 | The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for li... |
| CVE-2019-20096 | MEDIUM | 5.5 | 1.0% | Dec 30, 2019 | In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denia... |
| CVE-2019-20095 | MEDIUM | 5.5 | 0.4% | Dec 30, 2019 | mwifiex_tm_cmd in drivers/net/wireless/marvell/mwifiex/cfg80211.c in the Linux kernel before 5.1.6 has some error-handli... |
| CVE-2019-20094 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromg... |
| CVE-2019-20093 | MEDIUM | 5.5 | 1.4% | Dec 30, 2019 | The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial o... |
| CVE-2019-20092 | MEDIUM | 5.5 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ... |
| CVE-2019-20091 | MEDIUM | 5.5 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when ... |
| CVE-2019-20090 | HIGH | 7.8 | 0.8% | Dec 30, 2019 | An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when c... |
| CVE-2019-20089 | HIGH | 7.8 | 0.8% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has an heap-based buffer over-read in GPMF_SeekToSamples in GPMF_parse.c for the size calculatio... |
| CVE-2019-20088 | HIGH | 7.8 | 0.9% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GetPayload in GPMF_mp4reader.c. |
| CVE-2019-20087 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_seekToSamples in GPMF-parse.c for the "matching tags" ... |
| CVE-2019-20086 | HIGH | 8.8 | 1.0% | Dec 30, 2019 | GoPro GPMF-parser 1.2.3 has a heap-based buffer over-read in GPMF_Next in GPMF_parser.c. |
| CVE-2019-20085 | HIGH | 7.5 | 96.1% | Dec 30, 2019 | TVT NVMS-1000 devices allow GET /.. Directory Traversal |
| CVE-2019-20079 | HIGH | 7.8 | 1.9% | Dec 30, 2019 | The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory. |
| CVE-2019-20076 | MEDIUM | 6.1 | 1.4% | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configu... |
| CVE-2019-20075 | MEDIUM | 6.1 | 1.5% | Dec 30, 2019 | On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic). |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now