2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6153 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6151 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6152 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-6150 | — | — | — | Apr 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9497 | — | — | 5.4% | Apr 17, 2019 | The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element ... |
| CVE-2019-9496 | — | — | 5.2% | Apr 17, 2019 | An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps... |
| CVE-2019-7155 | — | — | 1.0% | Apr 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6... |
| CVE-2019-9845 | — | — | 2.5% | Apr 16, 2019 | madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG elemen... |
| CVE-2019-5520 | — | — | 1.0% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-5517 | — | — | 1.1% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-5516 | — | — | 1.7% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-6609 | — | — | 1.5% | Apr 15, 2019 | Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, An... |
| CVE-2019-11236 | — | — | 2.1% | Apr 15, 2019 | In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parame... |
| CVE-2019-0232 | — | — | 99.7% | Apr 15, 2019 | When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 ... |
| CVE-2019-11228 | — | — | 1.3% | Apr 15, 2019 | repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling S... |
| CVE-2019-11221 | — | — | 1.1% | Apr 15, 2019 | GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. |
| CVE-2019-1574 | — | — | 0.6% | Apr 12, 2019 | Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an... |
| CVE-2019-11213 | — | — | 2.8% | Apr 12, 2019 | In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof se... |
| CVE-2019-11196 | — | — | 6.3% | Apr 12, 2019 | An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allow... |
| CVE-2019-11191 | — | — | 0.5% | Apr 12, 2019 | The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass A... |
| CVE-2019-11190 | — | — | 0.5% | Apr 12, 2019 | The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_... |
| CVE-2019-9056 | — | — | 1.3% | Apr 11, 2019 | An issue was discovered in CMS Made Simple 2.2.8. In the module FrontEndUsers (in the file class.FrontEndUsersManipulate... |
| CVE-2019-7644 | — | — | 1.7% | Apr 11, 2019 | Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfull... |
| CVE-2019-6796 | — | — | 1.2% | Apr 11, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x befor... |
| CVE-2019-6493 | — | — | 0.5% | Apr 11, 2019 | SmartDefragDriver.sys (2.0) in IObit Smart Defrag 6 never frees an executable kernel pool that is allocated with user de... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now