2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7314 | — | — | 3.2% | Feb 4, 2019 | liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been... |
| CVE-2019-7313 | — | — | 0.9% | Feb 3, 2019 | www/resource.py in Buildbot before 1.8.1 allows CRLF injection in the Location header of /auth/login and /auth/logout vi... |
| CVE-2019-7312 | — | — | 1.1% | Feb 3, 2019 | Limited plaintext disclosure exists in PRIMX Zed Entreprise for Windows before 6.1.2240, Zed Entreprise for Windows (ANS... |
| CVE-2019-7309 | — | — | 0.6% | Feb 3, 2019 | In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly ret... |
| CVE-2019-7308 | — | — | 0.5% | Feb 1, 2019 | kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithm... |
| CVE-2019-7301 | — | — | 3.4% | Feb 1, 2019 | Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacha... |
| CVE-2019-7300 | — | — | 2.8% | Feb 1, 2019 | Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/setting... |
| CVE-2019-7298 | — | — | 10.1% | Feb 1, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allo... |
| CVE-2019-7297 | — | — | 12.5% | Jan 31, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware through 1.02B03. A command Injection vulnerability allo... |
| CVE-2019-7296 | — | — | 1.7% | Jan 31, 2019 | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formul... |
| CVE-2019-7295 | — | — | 1.7% | Jan 31, 2019 | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula... |
| CVE-2019-7250 | — | — | 0.8% | Jan 31, 2019 | An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configu... |
| CVE-2019-7249 | — | — | 2.5% | Jan 31, 2019 | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and woul... |
| CVE-2019-7216 | — | — | 2.0% | Jan 31, 2019 | An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user ... |
| CVE-2019-6438 | — | — | 2.3% | Jan 31, 2019 | SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. |
| CVE-2019-7237 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=... |
| CVE-2019-7236 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManage... |
| CVE-2019-7235 | — | — | 2.5% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../... |
| CVE-2019-7234 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../... |
| CVE-2019-7233 | — | — | 1.5% | Jan 30, 2019 | In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference. |
| CVE-2019-1565 | — | — | 0.7% | Jan 30, 2019 | The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier... |
| CVE-2019-7173 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7172 | — | — | 0.9% | Jan 29, 2019 | A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7171 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7170 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now