2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6442 | — | — | 13.7% | Jan 16, 2019 | An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a... |
| CVE-2019-6440 | — | — | 3.0% | Jan 16, 2019 | Zemana AntiMalware before 3.0.658 Beta mishandles update logic. |
| CVE-2019-6439 | — | — | 2.6% | Jan 16, 2019 | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow. |
| CVE-2019-3557 | — | — | 1.7% | Jan 15, 2019 | The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 co... |
| CVE-2019-3554 | — | — | 1.1% | Jan 15, 2019 | Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential den... |
| CVE-2019-6296 | — | — | 1.3% | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter. |
| CVE-2019-6295 | — | — | 1.3% | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter. |
| CVE-2019-6294 | — | — | 0.5% | Jan 15, 2019 | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/ca... |
| CVE-2019-6289 | — | — | 1.9% | Jan 15, 2019 | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by ... |
| CVE-2019-6293 | — | — | 1.6% | Jan 15, 2019 | An issue was discovered in the function mark_beginning_as_normal in nfa.c in flex 2.6.4. There is a stack exhaustion pro... |
| CVE-2019-6292 | — | — | 1.7% | Jan 15, 2019 | An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::Sin... |
| CVE-2019-6291 | — | — | 1.3% | Jan 15, 2019 | An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack ex... |
| CVE-2019-6290 | — | — | 1.3% | Jan 15, 2019 | An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhau... |
| CVE-2019-6267 | — | — | 1.4% | Jan 15, 2019 | The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is misha... |
| CVE-2019-6286 | — | — | 2.1% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called f... |
| CVE-2019-6285 | — | — | 2.5% | Jan 14, 2019 | The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a ... |
| CVE-2019-6278 | — | — | 0.5% | Jan 14, 2019 | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option. |
| CVE-2019-6259 | — | — | 1.5% | Jan 14, 2019 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data... |
| CVE-2019-6256 | — | — | 2.4% | Jan 14, 2019 | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. ... |
| CVE-2019-6251 | — | — | 4.1% | Jan 14, 2019 | WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirect... |
| CVE-2019-6250 | — | — | 9.4% | Jan 13, 2019 | A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_de... |
| CVE-2019-6249 | — | — | 3.0% | Jan 13, 2019 | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde... |
| CVE-2019-6248 | — | — | 0.7% | Jan 13, 2019 | PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demo... |
| CVE-2019-6247 | — | — | 2.5% | Jan 13, 2019 | An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflo... |
| CVE-2019-6246 | — | — | 1.8% | Jan 13, 2019 | An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now