2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3804 | HIGH | 7.5 | 4.9% | Mar 26, 2019 | It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial o... |
| CVE-2019-3606 | HIGH | 7.7 | 0.2% | Mar 26, 2019 | Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management... |
| CVE-2019-9061 | HIGH | 8.8 | 1.6% | Mar 26, 2019 | An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action.installmodule.php), it... |
| CVE-2019-9058 | HIGH | 7.2 | 1.2% | Mar 26, 2019 | An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to... |
| CVE-2019-9057 | HIGH | 8.8 | 1.6% | Mar 26, 2019 | An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to reach an unserialize call ... |
| CVE-2019-7642 | HIGH | 7.5 | 2.6% | Mar 25, 2019 | D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can re... |
| CVE-2019-0204 | HIGH | 7.8 | 2.7% | Mar 25, 2019 | A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru... |
| CVE-2019-7613 | HIGH | 7.5 | 1.3% | Mar 25, 2019 | Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain charact... |
| CVE-2019-7611 | HIGH | 8.1 | 2.1% | Mar 25, 2019 | A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Le... |
| CVE-2019-4046 | HIGH | 7.5 | 3.2% | Mar 25, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handlin... |
| CVE-2019-3879 | HIGH | 8.1 | 1.9% | Mar 25, 2019 | It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com... |
| CVE-2019-3857 | HIGH | 8.8 | 6.1% | Mar 25, 2019 | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS... |
| CVE-2019-3856 | HIGH | 8.8 | 6.1% | Mar 25, 2019 | An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way ... |
| CVE-2019-10012 | HIGH | 7.5 | 1.6% | Mar 25, 2019 | Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code... |
| CVE-2019-3863 | HIGH | 7.5 | 3.4% | Mar 25, 2019 | A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple... |
| CVE-2019-3841 | HIGH | 7.4 | 0.5% | Mar 25, 2019 | Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when ... |
| CVE-2019-3827 | HIGH | 7 | 0.4% | Mar 25, 2019 | An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modif... |
| CVE-2019-1766 | HIGH | 7.5 | 1.5% | Mar 22, 2019 | A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8... |
| CVE-2019-1765 | HIGH | 8.1 | 1.4% | Mar 22, 2019 | A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8... |
| CVE-2019-1764 | HIGH | 8.1 | 0.7% | Mar 22, 2019 | A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8... |
| CVE-2019-1763 | HIGH | 7.5 | 1.9% | Mar 22, 2019 | A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8... |
| CVE-2019-1716 | HIGH | 7.5 | 3.1% | Mar 22, 2019 | A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7... |
| CVE-2019-4052 | HIGH | 7.5 | 1.9% | Mar 22, 2019 | IBM API Connect 2018.1 and 2018.4.1.2 apis can be leveraged by unauthenticated users to discover login ids of registered... |
| CVE-2019-9924 | HIGH | 7.8 | 0.4% | Mar 22, 2019 | rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execut... |
| CVE-2019-9923 | HIGH | 7.5 | 3.0% | Mar 22, 2019 | pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that h... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now