2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16873 | MEDIUM | 5.4 | 0.5% | Nov 7, 2019 | Portainer before 1.22.1 has XSS (issue 1 of 2). |
| CVE-2019-12331 | HIGH | 8.8 | 1.4% | Nov 7, 2019 | PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if ... |
| CVE-2019-18805 | CRITICAL | 9.8 | 3.4% | Nov 7, 2019 | An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c... |
| CVE-2019-18804 | HIGH | 7.5 | 3.7% | Nov 7, 2019 | DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. |
| CVE-2019-15004 | HIGH | 7.5 | 3.9% | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ... |
| CVE-2019-15003 | MEDIUM | 5.3 | 1.7% | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ... |
| CVE-2019-16401 | MEDIUM | 6.5 | 0.5% | Nov 6, 2019 | Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon ... |
| CVE-2019-16400 | MEDIUM | 6.5 | 0.5% | Nov 6, 2019 | Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon ... |
| CVE-2019-18411 | HIGH | 8.8 | 2.3% | Nov 6, 2019 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are att... |
| CVE-2019-12419 | CRITICAL | 9.8 | 13.8% | Nov 6, 2019 | Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Conn... |
| CVE-2019-12406 | MEDIUM | 6.5 | 6.3% | Nov 6, 2019 | Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This ... |
| CVE-2019-5125 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially cra... |
| CVE-2019-5100 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A speciall... |
| CVE-2019-5099 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially craf... |
| CVE-2019-5084 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A special... |
| CVE-2019-5644 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a... |
| CVE-2019-5643 | MEDIUM | 5.3 | 0.9% | Nov 6, 2019 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.5 and earlier suffers from a... |
| CVE-2019-5642 | LOW | 3.3 | 0.3% | Nov 6, 2019 | Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server... |
| CVE-2019-5617 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | Computing For Good's Basic Laboratory Information System (also known as C4G BLIS) version 3.4 and earlier suffers from a... |
| CVE-2019-6122 | LOW | 3.1 | 1.0% | Nov 6, 2019 | A Username Enumeration via Error Message issue was discovered in NiceHash Miner before 2.0.3.0 because an "EMAIL DOES NO... |
| CVE-2019-6121 | LOW | 3.7 | 1.0% | Nov 6, 2019 | An issue was discovered in NiceHash Miner before 2.0.3.0. Missing Authorization allows an adversary to can gain access t... |
| CVE-2019-6120 | HIGH | 7.5 | 1.7% | Nov 6, 2019 | An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address a... |
| CVE-2019-2332 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Memory corruption while accessing the memory as payload size is not validated before access in Snapdragon Auto, Snapdrag... |
| CVE-2019-2331 | CRITICAL | 9.8 | 1.2% | Nov 6, 2019 | Possible Integer overflow because of subtracting two integers without checking if the result would overflow or not in Sn... |
| CVE-2019-2325 | CRITICAL | 9.8 | 0.9% | Nov 6, 2019 | Out of boundary access due to token received from ADSP and is used without validation as an index into the array in Snap... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now