2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19341 | MEDIUM | 5.5 | 0.3% | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab... |
| CVE-2019-19340 | HIGH | 8.2 | 1.5% | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where enabling RabbitMQ manager b... |
| CVE-2019-19234 | HIGH | 7.5 | 3.4% | Dec 19, 2019 | In Sudo through 1.8.29, the fact that a user has been blocked (e.g., by using the ! character in the shadow file instead... |
| CVE-2019-19232 | HIGH | 7.5 | 3.3% | Dec 19, 2019 | In Sudo through 1.8.29, an attacker with access to a Runas ALL sudoer account can impersonate a nonexistent user by invo... |
| CVE-2019-17527 | CRITICAL | 9.8 | 1.0% | Dec 19, 2019 | dataForDepandantField in models/custormfields.php in the JS JOBS FREE extension before 1.2.7 for Joomla! allows SQL Inje... |
| CVE-2019-16871 | CRITICAL | 9.8 | 5.3% | Dec 19, 2019 | Beckhoff Embedded Windows PLCs through 3.1.4024.0, and Beckhoff Twincat on Windows Engineering stations, allow an attack... |
| CVE-2019-8256 | CRITICAL | 9.8 | 4.0% | Dec 19, 2019 | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulner... |
| CVE-2019-8255 | CRITICAL | 9.8 | 6.6% | Dec 19, 2019 | Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitra... |
| CVE-2019-8254 | HIGH | 7.8 | 3.5% | Dec 19, 2019 | Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful ex... |
| CVE-2019-8253 | HIGH | 7.8 | 3.5% | Dec 19, 2019 | Adobe Photoshop CC versions before 20.0.8 and 21.0.x before 21.0.2 have a memory corruption vulnerability. Successful ex... |
| CVE-2019-11294 | MEDIUM | 4.3 | 0.8% | Dec 19, 2019 | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, i... |
| CVE-2019-19910 | MEDIUM | 6.1 | 0.7% | Dec 19, 2019 | The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, a... |
| CVE-2019-19909 | HIGH | 8.8 | 1.4% | Dec 19, 2019 | An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) ... |
| CVE-2019-18181 | HIGH | 7.8 | 0.3% | Dec 19, 2019 | In CloudVision Portal all releases in the 2018.1 and 2018.2 Code train allows users with read-only permissions to bypass... |
| CVE-2019-19907 | CRITICAL | 9.8 | 2.2% | Dec 19, 2019 | HrAddFBBlock in libfreebusy/freebusyutil.cpp in Kopano Groupware Core before 8.7.7 allows out-of-bounds access, as demon... |
| CVE-2019-19906 | HIGH | 7.5 | 8.0% | Dec 19, 2019 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in Ope... |
| CVE-2019-19905 | CRITICAL | 9.8 | 3.4% | Dec 19, 2019 | NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration f... |
| CVE-2019-18955 | MEDIUM | 6.1 | 0.6% | Dec 19, 2019 | The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed wit... |
| CVE-2019-18615 | MEDIUM | 4.9 | 0.5% | Dec 19, 2019 | In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user pa... |
| CVE-2019-17633 | HIGH | 8.8 | 0.8% | Dec 19, 2019 | For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could t... |
| CVE-2019-16465 | HIGH | 7.5 | 3.3% | Dec 19, 2019 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v... |
| CVE-2019-16464 | CRITICAL | 9.8 | 4.8% | Dec 19, 2019 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v... |
| CVE-2019-11780 | HIGH | 8.1 | 2.1% | Dec 19, 2019 | Improper access control in the computed fields system of the framework of Odoo Community 13.0 and Odoo Enterprise 13.0 a... |
| CVE-2019-16463 | CRITICAL | 9.8 | 5.4% | Dec 19, 2019 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v... |
| CVE-2019-16462 | CRITICAL | 9.8 | 4.8% | Dec 19, 2019 | Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now