2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2436 | MEDIUM | 5.5 | 2.1% | Jan 16, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that... |
| CVE-2019-2434 | MEDIUM | 6.5 | 3.3% | Jan 16, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are ... |
| CVE-2019-2420 | MEDIUM | 4.9 | 3.1% | Jan 16, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a... |
| CVE-2019-6462 | MEDIUM | 6.5 | 2.1% | Jan 16, 2019 | An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cai... |
| CVE-2019-6461 | MEDIUM | 6.5 | 2.1% | Jan 16, 2019 | An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the fi... |
| CVE-2019-0027 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Snort Rules configuration of Juniper ATP may allow authenti... |
| CVE-2019-0026 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated u... |
| CVE-2019-0025 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in RADIUS configuration menu of Juniper ATP may allow authenticate... |
| CVE-2019-0024 | MEDIUM | 5.4 | 0.6% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticate... |
| CVE-2019-0023 | MEDIUM | 5.4 | 0.5% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the Golden VM menu of Juniper ATP may allow authenticated user ... |
| CVE-2019-0018 | MEDIUM | 5.4 | 0.5% | Jan 15, 2019 | A persistent cross-site scripting (XSS) vulnerability in the file upload menu of Juniper ATP may allow an authenticated ... |
| CVE-2019-0017 | MEDIUM | 6.5 | 1.1% | Jan 15, 2019 | The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which ma... |
| CVE-2019-0016 | MEDIUM | 6.5 | 0.9% | Jan 15, 2019 | A malicious authenticated user may be able to delete a device from the Junos Space database without the necessary privil... |
| CVE-2019-0015 | MEDIUM | 5.4 | 0.8% | Jan 15, 2019 | A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections ... |
| CVE-2019-0013 | MEDIUM | 6.5 | 1.7% | Jan 15, 2019 | The routing protocol daemon (RPD) process will crash and restart when a specific invalid IPv4 PIM Join packet is receive... |
| CVE-2019-0011 | MEDIUM | 6.5 | 0.6% | Jan 15, 2019 | The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as... |
| CVE-2019-0009 | MEDIUM | 5.5 | 0.4% | Jan 15, 2019 | On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and ... |
| CVE-2019-0005 | MEDIUM | 5.3 | 1.2% | Jan 15, 2019 | On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any I... |
| CVE-2019-0004 | MEDIUM | 5.5 | 0.3% | Jan 15, 2019 | On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys ar... |
| CVE-2019-0003 | MEDIUM | 5.9 | 2.0% | Jan 15, 2019 | When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a speci... |
| CVE-2019-3811 | MEDIUM | 5.2 | 0.7% | Jan 15, 2019 | A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root ... |
| CVE-2019-6284 | MEDIUM | 6.5 | 2.1% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp. |
| CVE-2019-6283 | MEDIUM | 6.5 | 1.9% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp. |
| CVE-2019-3803 | MEDIUM | 4.5 | 0.6% | Jan 12, 2019 | Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote atta... |
| CVE-2019-6129 | MEDIUM | 6.5 | 1.4% | Jan 11, 2019 | png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has st... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now