2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19317 | CRITICAL | 9.8 | 4.3% | Dec 5, 2019 | lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which al... |
| CVE-2019-19601 | HIGH | 7.8 | 1.2% | Dec 5, 2019 | OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf. |
| CVE-2019-19598 | HIGH | 8.8 | 3.2% | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP... |
| CVE-2019-19597 | HIGH | 8.8 | 19.1% | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via sh... |
| CVE-2019-19589 | CRITICAL | 9.8 | 1.8% | Dec 5, 2019 | The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid... |
| CVE-2019-19596 | MEDIUM | 5.4 | 0.7% | Dec 5, 2019 | GitBook through 2.6.9 allows XSS via a local .md file. |
| CVE-2019-19590 | HIGH | 7.8 | 2.5% | Dec 5, 2019 | In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at ... |
| CVE-2019-19588 | HIGH | 7.5 | 1.2% | Dec 5, 2019 | The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a ... |
| CVE-2019-19553 | HIGH | 7.5 | 4.1% | Dec 5, 2019 | In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/as... |
| CVE-2019-19587 | MEDIUM | 6.1 | 0.6% | Dec 5, 2019 | In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the sou... |
| CVE-2019-19522 | HIGH | 7.8 | 0.5% | Dec 5, 2019 | OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to beco... |
| CVE-2019-19521 | CRITICAL | 9.8 | 2.7% | Dec 5, 2019 | libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiu... |
| CVE-2019-19520 | HIGH | 7.8 | 1.4% | Dec 5, 2019 | xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir... |
| CVE-2019-19519 | HIGH | 7.8 | 0.4% | Dec 5, 2019 | In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is ... |
| CVE-2019-19579 | MEDIUM | 6.8 | 0.5% | Dec 4, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where... |
| CVE-2019-16753 | HIGH | 7.5 | 0.7% | Dec 4, 2019 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is... |
| CVE-2019-16752 | MEDIUM | 4.3 | 0.4% | Dec 4, 2019 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wal... |
| CVE-2019-11216 | MEDIUM | 6.5 | 1.8% | Dec 4, 2019 | BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XM... |
| CVE-2019-19364 | HIGH | 7.8 | 0.5% | Dec 4, 2019 | A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and Cata... |
| CVE-2019-19229 | MEDIUM | 6.5 | 2.3% | Dec 4, 2019 | admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= D... |
| CVE-2019-19228 | CRITICAL | 9.8 | 1.9% | Dec 4, 2019 | Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password f... |
| CVE-2019-19133 | MEDIUM | 6.1 | 1.9% | Dec 4, 2019 | The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page requ... |
| CVE-2019-19576 | CRITICAL | 9.8 | 26.2% | Dec 4, 2019 | class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an... |
| CVE-2019-18347 | MEDIUM | 5.4 | 1.1% | Dec 4, 2019 | A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields tha... |
| CVE-2019-18346 | HIGH | 8.8 | 1.0% | Dec 4, 2019 | A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now