2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2564 | — | — | 0.9% | Apr 23, 2019 | Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime).... |
| CVE-2019-2558 | — | — | 1.2% | Apr 23, 2019 | Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Infrastructur... |
| CVE-2019-2557 | — | — | 5.5% | Apr 23, 2019 | Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen... |
| CVE-2019-2551 | — | — | 1.3% | Apr 23, 2019 | Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Su... |
| CVE-2019-2518 | — | — | 1.2% | Apr 23, 2019 | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.... |
| CVE-2019-2517 | — | — | 1.7% | Apr 23, 2019 | Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 a... |
| CVE-2019-2516 | — | — | 0.4% | Apr 23, 2019 | Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are ... |
| CVE-2019-2424 | — | — | 1.2% | Apr 23, 2019 | Vulnerability in the Oracle Retail Convenience Store Back Office component of Oracle Retail Applications (subcomponent: ... |
| CVE-2019-11076 | — | — | 3.5% | Apr 23, 2019 | Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request. |
| CVE-2019-10864 | — | — | 1.4% | Apr 23, 2019 | The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script... |
| CVE-2019-11473 | — | — | 2.4% | Apr 23, 2019 | coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application ... |
| CVE-2019-11472 | — | — | 3.4% | Apr 23, 2019 | ReadXWDImage in coders/xwd.c in the XWD image parsing component of ImageMagick 7.0.8-41 Q16 allows attackers to cause a ... |
| CVE-2019-11471 | — | — | 1.8% | Apr 23, 2019 | libheif 1.4.0 has a use-after-free in heif::HeifContext::Image::set_alpha_channel in heif_context.h because heif_context... |
| CVE-2019-11470 | — | — | 3.6% | Apr 23, 2019 | The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled res... |
| CVE-2019-11469 | — | — | 18.4% | Apr 23, 2019 | Zoho ManageEngine Applications Manager 12 through 14 allows FaultTemplateOptions.jsp resourceid SQL injection. Subsequen... |
| CVE-2019-11460 | — | — | 2.0% | Apr 22, 2019 | An issue was discovered in GNOME gnome-desktop 3.26, 3.28, and 3.30 prior to 3.30.2.2, and 3.32 prior to 3.32.1.1. A com... |
| CVE-2019-11383 | — | — | 1.6% | Apr 22, 2019 | An issue was discovered in the Medha WiFi FTP Server application 1.8.3 for Android. An attacker can read the username/pa... |
| CVE-2019-0218 | — | — | 5.1% | Apr 22, 2019 | A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mai... |
| CVE-2019-5428 | — | — | — | Apr 22, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of ... |
| CVE-2019-11461 | — | — | 0.3% | Apr 22, 2019 | An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may e... |
| CVE-2019-11384 | — | — | 1.0% | Apr 22, 2019 | The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), wh... |
| CVE-2019-10248 | — | — | 0.4% | Apr 22, 2019 | Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. An... |
| CVE-2019-9955 | — | — | 20.9% | Apr 22, 2019 | On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U... |
| CVE-2019-11456 | — | — | 0.9% | Apr 22, 2019 | Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code. |
| CVE-2019-11452 | — | — | 1.3% | Apr 22, 2019 | whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now