2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17334 | HIGH | 8 | 1.0% | Dec 17, 2019 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS ... |
| CVE-2019-19241 | HIGH | 7.8 | 1.1% | Dec 17, 2019 | In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili... |
| CVE-2019-0384 | HIGH | 8.8 | 0.9% | Dec 17, 2019 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F... |
| CVE-2019-0383 | HIGH | 8.8 | 1.1% | Dec 17, 2019 | Transaction Management in SAP Treasury and Risk Management (corrected in S4CORE versions 1.01, 1.02, 1.03, 1.04 and EA-F... |
| CVE-2019-19497 | MEDIUM | 5.4 | 0.6% | Dec 17, 2019 | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message. |
| CVE-2019-19634 | CRITICAL | 9.8 | 4.2% | Dec 17, 2019 | class.upload.php in verot.net class.upload through 1.0.3 and 2.x through 2.0.4, as used in the K2 extension for Joomla! ... |
| CVE-2019-19850 | HIGH | 7.2 | 0.9% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. Because escaping of user-subm... |
| CVE-2019-19849 | HIGH | 8.8 | 1.3% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t... |
| CVE-2019-19848 | HIGH | 7.2 | 1.5% | Dec 17, 2019 | An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that t... |
| CVE-2019-19847 | HIGH | 8.1 | 1.4% | Dec 17, 2019 | Libspiro through 20190731 has a stack-based buffer overflow in the spiro_to_bpath0() function in spiro.c. |
| CVE-2019-18956 | CRITICAL | 9.8 | 5.8% | Dec 17, 2019 | Divisa Proxia Suite 9 < 9.12.16, 9.11.19, 9.10.26, 9.9.8, 9.8.43 and 9.7.10, 10.0 < 10.0.32, and 10.1 < 10.1.5, SparkSpa... |
| CVE-2019-18670 | HIGH | 7.8 | 0.8% | Dec 17, 2019 | In the Quick Access Service (QAAdminAgent.exe) in Acer Quick Access V2.01.3000 through 2.01.3027 and V3.00.3000 through ... |
| CVE-2019-15235 | MEDIUM | 6.5 | 1.4% | Dec 17, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /ho... |
| CVE-2019-14782 | MEDIUM | 6.5 | 1.4% | Dec 17, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session ... |
| CVE-2019-19745 | HIGH | 8.8 | 1.1% | Dec 17, 2019 | Contao 4.0 through 4.8.5 allows PHP local file inclusion. A back end user with access to the form generator can upload a... |
| CVE-2019-19714 | MEDIUM | 5.3 | 0.8% | Dec 17, 2019 | Contao 4.8.4 and 4.8.5 has Improper Encoding or Escaping of Output. It is possible to inject insert tags into the login ... |
| CVE-2019-19675 | HIGH | 7.8 | 0.5% | Dec 17, 2019 | In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Appli... |
| CVE-2019-19315 | HIGH | 7.1 | 0.6% | Dec 17, 2019 | NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Priv... |
| CVE-2019-16576 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | A missing permission check in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers with Overall/Re... |
| CVE-2019-16575 | HIGH | 8.8 | 0.9% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Alauda Kubernetes Suport Plugin 2.3.0 and earlier allows attackers... |
| CVE-2019-16574 | MEDIUM | 6.5 | 0.9% | Dec 17, 2019 | A missing permission check in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers with Overall/Read... |
| CVE-2019-16573 | HIGH | 8.8 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins Alauda DevOps Pipeline Plugin 2.3.2 and earlier allows attackers t... |
| CVE-2019-16572 | MEDIUM | 5.5 | 0.3% | Dec 17, 2019 | Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins ma... |
| CVE-2019-16571 | MEDIUM | 4.3 | 0.7% | Dec 17, 2019 | A missing permission check in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers with Overall/Read permission t... |
| CVE-2019-16570 | HIGH | 8.8 | 0.7% | Dec 17, 2019 | A cross-site request forgery vulnerability in Jenkins RapidDeploy Plugin 4.1 and earlier allows attackers to connect to ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now