2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2534 | HIGH | 7.1 | 2.1% | Jan 16, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that... |
| CVE-2019-2435 | HIGH | 8.1 | 2.5% | Jan 16, 2019 | Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions tha... |
| CVE-2019-6447 | HIGH | 8.1 | 62.0% | Jan 16, 2019 | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi... |
| CVE-2019-0030 | HIGH | 7.2 | 0.5% | Jan 15, 2019 | Juniper ATP uses DES and a hardcoded salt for password hashing, allowing for trivial de-hashing of the password file con... |
| CVE-2019-0029 | HIGH | 8.8 | 0.3% | Jan 15, 2019 | Juniper ATP Series Splunk credentials are logged in a file readable by authenticated local users. Using these credential... |
| CVE-2019-0021 | HIGH | 7.1 | 0.3% | Jan 15, 2019 | On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing a... |
| CVE-2019-0014 | HIGH | 7.5 | 1.7% | Jan 15, 2019 | On QFX and PTX Series, receipt of a malformed packet for J-Flow sampling might crash the FPC (Flexible PIC Concentrator)... |
| CVE-2019-0012 | HIGH | 7.5 | 1.7% | Jan 15, 2019 | A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker t... |
| CVE-2019-0010 | HIGH | 7.5 | 2.7% | Jan 15, 2019 | An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the erro... |
| CVE-2019-0001 | HIGH | 7.5 | 3.0% | Jan 15, 2019 | Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion... |
| CVE-2019-6257 | HIGH | 7.7 | 1.1% | Jan 14, 2019 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the ... |
| CVE-2019-6245 | HIGH | 8.8 | 2.0% | Jan 13, 2019 | An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_a... |
| CVE-2019-6128 | HIGH | 8.8 | 3.9% | Jan 11, 2019 | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. |
| CVE-2019-5747 | HIGH | 7.5 | 4.7% | Jan 9, 2019 | An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP clien... |
| CVE-2019-0542 | HIGH | 8.8 | 3.2% | Jan 9, 2019 | A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Re... |
| CVE-2019-3581 | HIGH | 7.5 | 2.3% | Jan 9, 2019 | Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus... |
| CVE-2019-0582 | HIGH | 7.8 | 12.3% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0543 | HIGH | 7.8 | 4.7% | Jan 8, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W... |
| CVE-2019-0541 | HIGH | 8.8 | 53.2% | Jan 8, 2019 | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E... |
| CVE-2019-0538 | HIGH | 7.8 | 20.5% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-5009 | HIGH | 7.2 | 9.9% | Jan 4, 2019 | Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the upload... |
| CVE-2019-3500 | HIGH | 7.8 | 0.4% | Jan 2, 2019 | aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, whic... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now