2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17334HIGH8The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS ...
CVE-2019-19241HIGH7.8In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili...
CVE-2019-0384HIGH8.8Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F...
CVE-2019-0383HIGH8.8Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F...
CVE-2019-19497MEDIUM5.4MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
CVE-2019-19634CRITICAL9.8class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! ...
CVE-2019-19850HIGH7.2An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-subm...
CVE-2019-19849HIGH8.8An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t...
CVE-2019-19848HIGH7.2An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t...
CVE-2019-19847HIGH8.1Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c.
CVE-2019-18956CRITICAL9.8Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpa...
CVE-2019-18670HIGH7.8In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through ...
CVE-2019-15235MEDIUM6.5CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /ho...
CVE-2019-14782MEDIUM6.5CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session ...
CVE-2019-19745HIGH8.8Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload a...
CVE-2019-19714MEDIUM5.3Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login ...
CVE-2019-19675HIGH7.8In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli...
CVE-2019-19315HIGH7.1NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Priv...
CVE-2019-16576MEDIUM6.5A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Re...
CVE-2019-16575HIGH8.8A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers...
CVE-2019-16574MEDIUM6.5A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read...
CVE-2019-16573HIGH8.8A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers t...
CVE-2019-16572MEDIUM5.5Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ma...
CVE-2019-16571MEDIUM4.3A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission t...
CVE-2019-16570HIGH8.8A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now