2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1677 | MEDIUM | 4.6 | 0.4% | Feb 7, 2019 | A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-si... |
| CVE-2019-6517 | MEDIUM | 6.8 | 0.4% | Feb 6, 2019 | BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November ... |
| CVE-2019-3825 | MEDIUM | 6.3 | 0.5% | Feb 6, 2019 | A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp... |
| CVE-2019-3823 | MEDIUM | 4.3 | 4.3% | Feb 6, 2019 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-o... |
| CVE-2019-3820 | MEDIUM | 4.3 | 0.5% | Feb 6, 2019 | It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual action... |
| CVE-2019-7400 | MEDIUM | 6.1 | 5.6% | Feb 5, 2019 | Rukovoditel before 2.4.1 allows XSS. |
| CVE-2019-4038 | MEDIUM | 6.2 | 0.4% | Feb 4, 2019 | IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the ap... |
| CVE-2019-1000020 | MEDIUM | 6.5 | 3.2% | Feb 4, 2019 | libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: ... |
| CVE-2019-1000019 | MEDIUM | 6.5 | 3.4% | Feb 4, 2019 | libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: ... |
| CVE-2019-7317 | MEDIUM | 5.3 | 9.4% | Feb 4, 2019 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called und... |
| CVE-2019-3604 | MEDIUM | 4.8 | 0.4% | Feb 1, 2019 | Cross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform uni... |
| CVE-2019-7282 | MEDIUM | 5.9 | 2.1% | Jan 31, 2019 | In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the... |
| CVE-2019-6111 | MEDIUM | 5.9 | 58.2% | Jan 31, 2019 | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh... |
| CVE-2019-6110 | MEDIUM | 6.8 | 20.9% | Jan 31, 2019 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T... |
| CVE-2019-6109 | MEDIUM | 6.8 | 3.8% | Jan 31, 2019 | An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o... |
| CVE-2019-4040 | MEDIUM | 6.1 | 1.3% | Jan 31, 2019 | IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2019-3913 | MEDIUM | 4.9 | 1.7% | Jan 30, 2019 | Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker ... |
| CVE-2019-3912 | MEDIUM | 6.1 | 4.8% | Jan 30, 2019 | An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL param... |
| CVE-2019-3911 | MEDIUM | 6.1 | 3.8% | Jan 30, 2019 | Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an ... |
| CVE-2019-1566 | MEDIUM | 6.1 | 1.2% | Jan 30, 2019 | The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlie... |
| CVE-2019-7154 | MEDIUM | 6.5 | 1.1% | Jan 29, 2019 | The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misuse... |
| CVE-2019-7153 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when c... |
| CVE-2019-7152 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (whe... |
| CVE-2019-7151 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A cra... |
| CVE-2019-7150 | MEDIUM | 5.5 | 1.4% | Jan 29, 2019 | An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now