2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6556 | — | — | 1.2% | Apr 10, 2019 | When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 a... |
| CVE-2019-0229 | — | — | 1.5% | Apr 10, 2019 | A number of HTTP endpoints in the Airflow webserver (both RBAC and classic) did not have adequate protection and were vu... |
| CVE-2019-0216 | — | — | 2.8% | Apr 10, 2019 | A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript ... |
| CVE-2019-0034 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was withdrawn by its CNA. Further investigatio... |
| CVE-2019-10946 | — | — | 1.1% | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The "refresh list of helpsites" endpoint of com_users lacks access chec... |
| CVE-2019-10945 | — | — | 38.0% | Apr 10, 2019 | An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param... |
| CVE-2019-0208 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-7139 | — | — | 17.4% | Apr 10, 2019 | An unauthenticated user can execute SQL statements that allow arbitrary read access to the underlying database, which ca... |
| CVE-2019-5425 | — | — | 1.9% | Apr 10, 2019 | In Ubiquiti Networks EdgeSwitch X v1.1.0 and prior, an authenticated user can execute arbitrary shell commands over the ... |
| CVE-2019-6156 | — | — | 0.2% | Apr 10, 2019 | In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient prot... |
| CVE-2019-6287 | — | — | 1.0% | Apr 10, 2019 | In Rancher 2.0.0 through 2.1.5, project members have continued access to create, update, read, and delete namespaces in ... |
| CVE-2019-0199 | — | — | 72.9% | Apr 10, 2019 | The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive number... |
| CVE-2019-10843 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9696 | — | — | 1.1% | Apr 9, 2019 | Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a ty... |
| CVE-2019-5585 | — | — | 0.4% | Apr 9, 2019 | An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application'... |
| CVE-2019-0879 | — | — | 9.8% | Apr 9, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0877 | — | — | 4.9% | Apr 9, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0875 | — | — | 3.0% | Apr 9, 2019 | An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissio... |
| CVE-2019-0874 | — | — | 2.0% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu... |
| CVE-2019-0871 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0870 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0869 | — | — | 2.0% | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azu... |
| CVE-2019-0868 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0867 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0866 | — | — | 2.6% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now