2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18601 | HIGH | 7.5 | 1.4% | Oct 29, 2019 | OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to denial of service from unserialized data access because remote ... |
| CVE-2019-16647 | HIGH | 7.2 | 2.0% | Oct 29, 2019 | Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows. |
| CVE-2019-15683 | CRITICAL | 9.8 | 19.4% | Oct 29, 2019 | TurboVNC server code contains stack buffer overflow vulnerability in commit prior to cea98166008301e614e0d36776bf9435a53... |
| CVE-2019-15681 | HIGH | 7.5 | 3.3% | Oct 29, 2019 | LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which... |
| CVE-2019-15680 | HIGH | 7.5 | 2.8% | Oct 29, 2019 | TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which results Denial of System... |
| CVE-2019-15679 | CRITICAL | 9.8 | 12.8% | Oct 29, 2019 | TightVNC code version 1.3.10 contains heap buffer overflow in InitialiseRFBConnection function, which can potentially re... |
| CVE-2019-15678 | CRITICAL | 9.8 | 13.1% | Oct 29, 2019 | TightVNC code version 1.3.10 contains heap buffer overflow in rfbServerCutText handler, which can potentially result cod... |
| CVE-2019-13066 | MEDIUM | 6.1 | 1.0% | Oct 29, 2019 | Sahi Pro 8.0.0 has a script manager arena located at _s_/dyn/pro/DBReports with many different areas that are vulnerable... |
| CVE-2019-10749 | CRITICAL | 9.8 | 1.2% | Oct 29, 2019 | sequelize before version 3.35.1 allows attackers to perform a SQL Injection due to the JSON path keys not being properly... |
| CVE-2019-10748 | CRITICAL | 9.8 | 1.3% | Oct 29, 2019 | Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not bei... |
| CVE-2019-10743 | MEDIUM | 5.5 | 6.5% | Oct 29, 2019 | All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited usin... |
| CVE-2019-10211 | CRITICAL | 9.8 | 1.9% | Oct 29, 2019 | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL execu... |
| CVE-2019-10210 | HIGH | 7 | 0.4% | Oct 29, 2019 | Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing pas... |
| CVE-2019-10209 | LOW | 2.2 | 1.1% | Oct 29, 2019 | Postgresql, versions 11.x before 11.5, is vulnerable to a memory disclosure in cross-type comparison for hashed subplan. |
| CVE-2019-10208 | HIGH | 8.8 | 2.2% | Oct 29, 2019 | A flaw was discovered in postgresql versions 9.4.x before 9.4.24, 9.5.x before 9.5.19, 9.6.x before 9.6.15, 10.x before ... |
| CVE-2019-0210 | HIGH | 7.5 | 6.8% | Oct 29, 2019 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when f... |
| CVE-2019-0205 | HIGH | 7.5 | 9.1% | Oct 29, 2019 | In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with... |
| CVE-2019-4600 | MEDIUM | 5.3 | 1.4% | Oct 29, 2019 | IBM API Connect version V5.0.0.0 through 5.0.8.7 could reveal sensitive information to an attacker using a specially cra... |
| CVE-2019-4546 | HIGH | 8.8 | 0.7% | Oct 29, 2019 | After installing the IBM Maximo Health- Safety and Environment Manager 7.6.1, a user is granted additional privileges th... |
| CVE-2019-4339 | HIGH | 7.5 | 1.0% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2019-4330 | MEDIUM | 4.3 | 1.1% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions... |
| CVE-2019-4329 | MEDIUM | 4.3 | 0.9% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses incomplete blacklisting for input validation which allows ... |
| CVE-2019-4314 | HIGH | 7.5 | 1.0% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource tha... |
| CVE-2019-4311 | MEDIUM | 5.3 | 1.2% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The info... |
| CVE-2019-4309 | MEDIUM | 5.5 | 0.3% | Oct 29, 2019 | IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses hard coded credentials which could allow a local user to o... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now