2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18925 | CRITICAL | 9.8 | 1.4% | Nov 12, 2019 | Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication. |
| CVE-2019-18924 | MEDIUM | 5.3 | 1.3% | Nov 12, 2019 | Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with .... |
| CVE-2019-18655 | CRITICAL | 9.8 | 14.7% | Nov 12, 2019 | File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera... |
| CVE-2019-17237 | HIGH | 8.8 | 0.7% | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF. |
| CVE-2019-17236 | MEDIUM | 6.1 | 1.0% | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS. |
| CVE-2019-17235 | MEDIUM | 5.3 | 1.4% | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure. |
| CVE-2019-17234 | HIGH | 7.5 | 3.2% | Nov 12, 2019 | includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary... |
| CVE-2019-4652 | HIGH | 7.1 | 0.3% | Nov 12, 2019 | IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Wind... |
| CVE-2019-18848 | HIGH | 7.5 | 1.3% | Nov 12, 2019 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. |
| CVE-2019-18817 | HIGH | 7.5 | 1.2% | Nov 12, 2019 | Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related... |
| CVE-2019-18658 | CRITICAL | 9.8 | 1.7% | Nov 12, 2019 | In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport... |
| CVE-2019-18882 | MEDIUM | 6.1 | 0.6% | Nov 12, 2019 | WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled. |
| CVE-2019-18881 | MEDIUM | 6.1 | 0.7% | Nov 12, 2019 | WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile. |
| CVE-2019-18874 | HIGH | 7.5 | 3.5% | Nov 12, 2019 | psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a wh... |
| CVE-2019-18873 | CRITICAL | 9 | 8.2% | Nov 12, 2019 | FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An ... |
| CVE-2019-18862 | HIGH | 7.8 | 1.1% | Nov 11, 2019 | maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. |
| CVE-2019-18857 | HIGH | 7.5 | 1.0% | Nov 11, 2019 | darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected w... |
| CVE-2019-18856 | HIGH | 7.5 | 1.4% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to... |
| CVE-2019-18855 | HIGH | 7.5 | 2.6% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to p... |
| CVE-2019-18854 | HIGH | 7.5 | 2.6% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to u... |
| CVE-2019-18853 | MEDIUM | 6.5 | 1.5% | Nov 11, 2019 | ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly r... |
| CVE-2019-18852 | CRITICAL | 9.8 | 1.5% | Nov 11, 2019 | Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign ... |
| CVE-2019-18849 | MEDIUM | 5.5 | 1.2% | Nov 11, 2019 | In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message ... |
| CVE-2019-18841 | HIGH | 7.3 | 1.4% | Nov 11, 2019 | Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. |
| CVE-2019-18836 | HIGH | 7.5 | 1.9% | Nov 11, 2019 | Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connectio... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now