2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0688 | — | — | 7.9% | Apr 9, 2019 | An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, a... |
| CVE-2019-0685 | — | — | 1.6% | Apr 9, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2019-7361 | — | — | 1.4% | Apr 9, 2019 | An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trig... |
| CVE-2019-7360 | — | — | 1.6% | Apr 9, 2019 | An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Au... |
| CVE-2019-7359 | — | — | 1.6% | Apr 9, 2019 | An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk Au... |
| CVE-2019-7358 | — | — | 1.6% | Apr 9, 2019 | An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Aut... |
| CVE-2019-5513 | — | — | 1.2% | Apr 9, 2019 | VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosu... |
| CVE-2019-5512 | — | — | 1.2% | Apr 9, 2019 | VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately... |
| CVE-2019-5511 | — | — | 0.4% | Apr 9, 2019 | VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Succ... |
| CVE-2019-1567 | — | — | 0.6% | Apr 9, 2019 | The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ... |
| CVE-2019-7174 | — | — | 1.7% | Apr 9, 2019 | Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), f... |
| CVE-2019-6117 | — | — | 1.0% | Apr 9, 2019 | The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function. |
| CVE-2019-3941 | — | — | 2.4% | Apr 9, 2019 | Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC. |
| CVE-2019-3940 | — | — | 4.1% | Apr 9, 2019 | Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote ... |
| CVE-2019-10244 | — | — | 1.8% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and t... |
| CVE-2019-10243 | — | — | 1.3% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used... |
| CVE-2019-10242 | — | — | 2.0% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially a... |
| CVE-2019-11028 | — | — | 2.7% | Apr 9, 2019 | GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to... |
| CVE-2019-10634 | — | — | 0.8% | Apr 9, 2019 | An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitr... |
| CVE-2019-10633 | — | — | 3.3% | Apr 9, 2019 | An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a re... |
| CVE-2019-10632 | — | — | 1.4% | Apr 9, 2019 | A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a l... |
| CVE-2019-10631 | — | — | 2.3% | Apr 9, 2019 | Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated a... |
| CVE-2019-10630 | — | — | 1.2% | Apr 9, 2019 | A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin... |
| CVE-2019-10902 | — | — | 4.7% | Apr 9, 2019 | In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting s... |
| CVE-2019-10900 | — | — | 4.5% | Apr 9, 2019 | In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c b... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now