2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19646 | CRITICAL | 9.8 | 5.4% | Dec 9, 2019 | pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated... |
| CVE-2019-19603 | HIGH | 7.5 | 8.3% | Dec 9, 2019 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. |
| CVE-2019-18190 | CRITICAL | 9.8 | 2.7% | Dec 9, 2019 | Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors res... |
| CVE-2019-19687 | HIGH | 8.8 | 1.8% | Dec 9, 2019 | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a ... |
| CVE-2019-18380 | MEDIUM | 6.5 | 0.6% | Dec 9, 2019 | Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue... |
| CVE-2019-12424 | — | — | — | Dec 9, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-19685 | HIGH | 8.8 | 0.5% | Dec 9, 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and ... |
| CVE-2019-19684 | HIGH | 8.8 | 1.6% | Dec 9, 2019 | nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginCon... |
| CVE-2019-19683 | CRITICAL | 9.1 | 1.8% | Dec 9, 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to ../ path traversal via d or f to Admin/RoxyFileman/Pro... |
| CVE-2019-19682 | MEDIUM | 4.8 | 0.6% | Dec 9, 2019 | nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Control... |
| CVE-2019-14251 | HIGH | 7.5 | 7.8% | Dec 9, 2019 | An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a docu... |
| CVE-2019-19679 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condi... |
| CVE-2019-19678 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic f... |
| CVE-2019-19645 | MEDIUM | 5.5 | 0.6% | Dec 9, 2019 | alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential vi... |
| CVE-2019-19648 | HIGH | 7.8 | 1.6% | Dec 9, 2019 | In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real si... |
| CVE-2019-19647 | HIGH | 7.8 | 1.6% | Dec 9, 2019 | radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ul... |
| CVE-2019-19642 | HIGH | 8.8 | 19.0% | Dec 8, 2019 | On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command I... |
| CVE-2019-19638 | CRITICAL | 9.8 | 1.2% | Dec 8, 2019 | An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, ... |
| CVE-2019-19637 | CRITICAL | 9.8 | 1.2% | Dec 8, 2019 | An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsix... |
| CVE-2019-19636 | CRITICAL | 9.8 | 1.2% | Dec 8, 2019 | An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c. |
| CVE-2019-19635 | CRITICAL | 9.8 | 1.2% | Dec 8, 2019 | An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl a... |
| CVE-2019-19630 | HIGH | 7.8 | 1.1% | Dec 8, 2019 | HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_con... |
| CVE-2019-19449 | HIGH | 7.8 | 2.0% | Dec 8, 2019 | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_... |
| CVE-2019-19448 | HIGH | 7.8 | 2.2% | Dec 8, 2019 | In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then m... |
| CVE-2019-19447 | HIGH | 7.8 | 3.5% | Dec 8, 2019 | In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lea... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now