2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6144 | MEDIUM | 6.5 | 1.0% | Oct 23, 2019 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08... |
| CVE-2019-3982 | MEDIUM | 6.5 | 1.8% | Oct 23, 2019 | Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of ... |
| CVE-2019-18357 | MEDIUM | 6.1 | 0.8% | Oct 23, 2019 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2). |
| CVE-2019-18356 | MEDIUM | 6.1 | 0.8% | Oct 23, 2019 | An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2). |
| CVE-2019-18355 | CRITICAL | 9.8 | 1.5% | Oct 23, 2019 | An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7. |
| CVE-2019-18350 | MEDIUM | 6.1 | 1.1% | Oct 23, 2019 | In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, lea... |
| CVE-2019-18348 | MEDIUM | 6.1 | 3.5% | Oct 23, 2019 | An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection i... |
| CVE-2019-17606 | MEDIUM | 6.1 | 1.0% | Oct 23, 2019 | The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XS... |
| CVE-2019-17093 | HIGH | 7.8 | 0.6% | Oct 23, 2019 | An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability all... |
| CVE-2019-16977 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable comi... |
| CVE-2019-16975 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-11933 | CRITICAL | 9.8 | 4.1% | Oct 23, 2019 | A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19... |
| CVE-2019-11283 | HIGH | 8.8 | 1.5% | Oct 23, 2019 | Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote use... |
| CVE-2019-11282 | MEDIUM | 4.3 | 1.1% | Oct 23, 2019 | Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote... |
| CVE-2019-18344 | CRITICAL | 9.8 | 1.4% | Oct 23, 2019 | Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers t... |
| CVE-2019-18281 | MEDIUM | 4.3 | 2.1% | Oct 23, 2019 | An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12... |
| CVE-2019-16976 | MEDIUM | 6.1 | 0.7% | Oct 23, 2019 | In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable ... |
| CVE-2019-18280 | HIGH | 8.8 | 0.5% | Oct 23, 2019 | Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF... |
| CVE-2019-18278 | HIGH | 7.8 | 0.4% | Oct 23, 2019 | When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow st... |
| CVE-2019-18277 | HIGH | 7.5 | 10.0% | Oct 23, 2019 | A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chu... |
| CVE-2019-18220 | HIGH | 8.8 | 1.1% | Oct 23, 2019 | Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to valid... |
| CVE-2019-18219 | MEDIUM | 6.1 | 0.9% | Oct 23, 2019 | Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The a... |
| CVE-2019-10476 | HIGH | 7.8 | 0.3% | Oct 23, 2019 | Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ma... |
| CVE-2019-10475 | MEDIUM | 6.1 | 57.7% | Oct 23, 2019 | A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML... |
| CVE-2019-10474 | MEDIUM | 4.3 | 0.7% | Oct 23, 2019 | A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the sc... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now