2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17555 | HIGH | 7.5 | 2.1% | Dec 4, 2019 | The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it t... |
| CVE-2019-7201 | HIGH | 7.8 | 0.3% | Dec 4, 2019 | An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul... |
| CVE-2019-7197 | MEDIUM | 4.8 | 1.2% | Dec 4, 2019 | A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, th... |
| CVE-2019-19555 | MEDIUM | 5.5 | 1.1% | Dec 4, 2019 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. |
| CVE-2019-17556 | CRITICAL | 9.8 | 3.6% | Dec 4, 2019 | Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and... |
| CVE-2019-17554 | MEDIUM | 5.5 | 12.2% | Dec 4, 2019 | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti... |
| CVE-2019-11940 | CRITICAL | 9.8 | 1.4% | Dec 4, 2019 | In the course of decompressing HPACK inside the HTTP2 protocol, an unexpected sequence of header table resize operations... |
| CVE-2019-11936 | CRITICAL | 9.8 | 1.5% | Dec 4, 2019 | Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue a... |
| CVE-2019-11935 | CRITICAL | 9.8 | 1.5% | Dec 4, 2019 | Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This iss... |
| CVE-2019-11934 | CRITICAL | 9.8 | 1.7% | Dec 4, 2019 | Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly... |
| CVE-2019-11930 | CRITICAL | 9.8 | 3.2% | Dec 4, 2019 | An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. Th... |
| CVE-2019-11937 | HIGH | 7.5 | 1.4% | Dec 4, 2019 | In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhausti... |
| CVE-2019-11923 | HIGH | 7.5 | 1.5% | Dec 4, 2019 | In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no max... |
| CVE-2019-15638 | HIGH | 7.8 | 0.3% | Dec 4, 2019 | COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element. |
| CVE-2019-14909 | HIGH | 8.3 | 1.1% | Dec 4, 2019 | A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any pa... |
| CVE-2019-18850 | HIGH | 7.5 | 1.2% | Dec 4, 2019 | TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding ... |
| CVE-2019-5164 | HIGH | 7.8 | 0.7% | Dec 3, 2019 | An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafte... |
| CVE-2019-5163 | HIGH | 7.5 | 2.3% | Dec 3, 2019 | An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti... |
| CVE-2019-5133 | HIGH | 8.8 | 3.2% | Dec 3, 2019 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library.... |
| CVE-2019-5132 | HIGH | 8.8 | 3.7% | Dec 3, 2019 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear... |
| CVE-2019-5112 | HIGH | 8.8 | 1.6% | Dec 3, 2019 | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.... |
| CVE-2019-5111 | HIGH | 8.8 | 1.4% | Dec 3, 2019 | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.... |
| CVE-2019-5110 | HIGH | 8.8 | 1.1% | Dec 3, 2019 | Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web r... |
| CVE-2019-5109 | HIGH | 8.8 | 1.1% | Dec 3, 2019 | Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web ... |
| CVE-2019-5097 | HIGH | 7.5 | 45.1% | Dec 3, 2019 | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web serv... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now