2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14822 | HIGH | 7.1 | 0.4% | Nov 25, 2019 | A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method cal... |
| CVE-2019-14891 | MEDIUM | 5 | 0.7% | Nov 25, 2019 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can res... |
| CVE-2019-14815 | HIGH | 7.8 | 0.5% | Nov 25, 2019 | A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marve... |
| CVE-2019-10214 | MEDIUM | 5.9 | 1.6% | Nov 25, 2019 | The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version... |
| CVE-2019-10174 | HIGH | 8.8 | 3.1% | Nov 25, 2019 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allow... |
| CVE-2019-11287 | HIGH | 7.5 | 4.5% | Nov 23, 2019 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x ver... |
| CVE-2019-11291 | MEDIUM | 4.8 | 0.8% | Nov 22, 2019 | Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions p... |
| CVE-2019-18910 | MEDIUM | 6.8 | 0.8% | Nov 22, 2019 | The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker t... |
| CVE-2019-18909 | HIGH | 8 | 2.2% | Nov 22, 2019 | The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to ... |
| CVE-2019-16287 | MEDIUM | 6.8 | 0.7% | Nov 22, 2019 | In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerabi... |
| CVE-2019-16286 | MEDIUM | 6.8 | 0.8% | Nov 22, 2019 | An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by chang... |
| CVE-2019-16285 | MEDIUM | 4.6 | 1.0% | Nov 22, 2019 | If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extra... |
| CVE-2019-15593 | MEDIUM | 6.5 | 1.5% | Nov 22, 2019 | GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a D... |
| CVE-2019-18622 | CRITICAL | 9.8 | 2.6% | Nov 22, 2019 | An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection... |
| CVE-2019-13566 | CRITICAL | 9.8 | 3.1% | Nov 22, 2019 | An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3... |
| CVE-2019-3654 | HIGH | 8.6 | 0.7% | Nov 22, 2019 | Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l... |
| CVE-2019-19240 | MEDIUM | 5.3 | 1.5% | Nov 22, 2019 | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us... |
| CVE-2019-16763 | MEDIUM | 6.1 | 0.7% | Nov 22, 2019 | In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS a... |
| CVE-2019-9536 | MEDIUM | 6.8 | 0.5% | Nov 22, 2019 | Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. ... |
| CVE-2019-18610 | HIGH | 8.8 | 29.6% | Nov 22, 2019 | An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 1... |
| CVE-2019-17446 | HIGH | 7.8 | 0.3% | Nov 22, 2019 | An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operatio... |
| CVE-2019-17445 | MEDIUM | 5.5 | 0.3% | Nov 22, 2019 | An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in... |
| CVE-2019-15652 | MEDIUM | 6.1 | 0.9% | Nov 22, 2019 | The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for... |
| CVE-2019-18976 | HIGH | 7.5 | 6.7% | Nov 22, 2019 | An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If i... |
| CVE-2019-18790 | MEDIUM | 6.5 | 2.0% | Nov 22, 2019 | An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x bef... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now