2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13347 | HIGH | 7.5 | 1.1% | Dec 13, 2019 | An issue was discovered in the SAML Single Sign On (SSO) plugin for several Atlassian products affecting versions 3.1.0 ... |
| CVE-2019-19782 | CRITICAL | 9.8 | 3.2% | Dec 13, 2019 | The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server. |
| CVE-2019-19778 | HIGH | 8.8 | 1.4% | Dec 13, 2019 | An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c... |
| CVE-2019-19777 | HIGH | 8.8 | 1.4% | Dec 13, 2019 | stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read i... |
| CVE-2019-16777 | MEDIUM | 6.5 | 2.0% | Dec 13, 2019 | Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing glob... |
| CVE-2019-16776 | HIGH | 8.1 | 3.3% | Dec 13, 2019 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders... |
| CVE-2019-16775 | MEDIUM | 6.5 | 3.3% | Dec 13, 2019 | Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create... |
| CVE-2019-16774 | CRITICAL | 9.8 | 1.2% | Dec 12, 2019 | In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. |
| CVE-2019-12420 | HIGH | 7.5 | 7.2% | Dec 12, 2019 | In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3... |
| CVE-2019-5144 | HIGH | 8.8 | 2.4% | Dec 12, 2019 | An exploitable heap underflow vulnerability exists in the derive_taps_and_gains function in kdu_v7ar.dll of Kakadu Softw... |
| CVE-2019-5062 | MEDIUM | 6.5 | 0.5% | Dec 12, 2019 | An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for hostapd 2.6 connected c... |
| CVE-2019-5061 | MEDIUM | 6.5 | 0.9% | Dec 12, 2019 | An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAP... |
| CVE-2019-3951 | CRITICAL | 9.8 | 3.6% | Dec 12, 2019 | Advantech WebAccess before 8.4.3 allows unauthenticated remote attackers to execute arbitrary code or cause a denial of ... |
| CVE-2019-19771 | HIGH | 8.8 | 1.3% | Dec 12, 2019 | The lodahs package 0.0.1 for Node.js is a Trojan horse, and may have been installed by persons who mistyped the lodash p... |
| CVE-2019-19770 | HIGH | 8.2 | 2.4% | Dec 12, 2019 | In the Linux kernel 4.19.83, there is a use-after-free (read) in the debugfs_remove function in fs/debugfs/inode.c (whic... |
| CVE-2019-19769 | MEDIUM | 6.7 | 1.3% | Dec 12, 2019 | In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include... |
| CVE-2019-19768 | HIGH | 7.5 | 4.2% | Dec 12, 2019 | In the Linux kernel 5.4.0-rc2, there is a use-after-free (read) in the __blk_add_trace function in kernel/trace/blktrace... |
| CVE-2019-19767 | MEDIUM | 5.5 | 2.1% | Dec 12, 2019 | The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_exp... |
| CVE-2019-19766 | HIGH | 7.5 | 1.3% | Dec 12, 2019 | The Bitwarden server through 1.32.0 has a potentially unwanted KDF. |
| CVE-2019-18342 | CRITICAL | 9.9 | 2.1% | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po... |
| CVE-2019-18341 | MEDIUM | 5.3 | 1.6% | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The SFTP service (default po... |
| CVE-2019-18340 | MEDIUM | 5.5 | 0.3% | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), Control Center Server (CCS) ... |
| CVE-2019-18339 | CRITICAL | 9.8 | 2.7% | Dec 12, 2019 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The HTTP service (default port ... |
| CVE-2019-18338 | HIGH | 7.7 | 2.6% | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (C... |
| CVE-2019-18337 | CRITICAL | 9.8 | 2.5% | Dec 12, 2019 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (C... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now