2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0050 | HIGH | 7.5 | 1.3% | Oct 9, 2019 | Under certain heavy traffic conditions srxpfe process can crash and result in a denial of service condition for the SRX1... |
| CVE-2019-0047 | HIGH | 8.8 | 1.6% | Oct 9, 2019 | A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attac... |
| CVE-2019-5507 | MEDIUM | 5.5 | 0.4% | Oct 9, 2019 | SnapManager for Oracle prior to version 3.4.2P1 are susceptible to a vulnerability which when successfully exploited cou... |
| CVE-2019-5506 | MEDIUM | 5.9 | 0.8% | Oct 9, 2019 | Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making the... |
| CVE-2019-17402 | MEDIUM | 6.5 | 1.9% | Oct 9, 2019 | Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffD... |
| CVE-2019-17401 | LOW | 3.3 | 0.4% | Oct 9, 2019 | libyal liblnk 20191006 has a heap-based buffer over-read in the network_share_name_offset>20 code block of liblnk_locati... |
| CVE-2019-17092 | MEDIUM | 6.1 | 1.7% | Oct 9, 2019 | An XSS vulnerability in project list in OpenProject before 9.0.4 and 10.x before 10.0.2 allows remote attackers to injec... |
| CVE-2019-17399 | CRITICAL | 9.8 | 1.7% | Oct 9, 2019 | The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment. |
| CVE-2019-17389 | HIGH | 7.5 | 1.4% | Oct 9, 2019 | In RIOT 2019.07, the MQTT-SN implementation (asymcute) mishandles errors occurring during a read operation on a UDP sock... |
| CVE-2019-6471 | MEDIUM | 5.9 | 3.3% | Oct 9, 2019 | A race condition which may occur when discarding malformed packets can result in BIND exiting due to a REQUIRE assertion... |
| CVE-2019-6469 | HIGH | 7.5 | 1.9% | Oct 9, 2019 | An error in the EDNS Client Subnet (ECS) feature for recursive resolvers can cause BIND to exit with an assertion failur... |
| CVE-2019-6468 | HIGH | 7.5 | 2.5% | Oct 9, 2019 | In BIND Supported Preview Edition, an error in the nxdomain-redirect feature can occur in versions which support EDNS Cl... |
| CVE-2019-6467 | HIGH | 7.5 | 5.4% | Oct 9, 2019 | A programming error in the nxdomain-redirect feature can cause an assertion failure in query.c if the alternate namespac... |
| CVE-2019-6465 | MEDIUM | 5.3 | 3.7% | Oct 9, 2019 | Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable V... |
| CVE-2019-4558 | HIGH | 7.8 | 1.2% | Oct 9, 2019 | A security vulnerability has been identified in all levels of IBM Spectrum Scale V5.0.0.0 through V5.0.3.2 and IBM Spect... |
| CVE-2019-4512 | MEDIUM | 4.3 | 1.0% | Oct 9, 2019 | IBM Maximo Asset Management 7.6.1.1 generates an error message that includes sensitive information that could be used in... |
| CVE-2019-3653 | MEDIUM | 5.5 | 0.2% | Oct 9, 2019 | Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 20... |
| CVE-2019-3652 | MEDIUM | 5.3 | 0.3% | Oct 9, 2019 | Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows... |
| CVE-2019-17385 | MEDIUM | 6.1 | 0.9% | Oct 9, 2019 | The animate-it plugin before 2.3.5 for WordPress has XSS. |
| CVE-2019-17384 | MEDIUM | 6.1 | 0.9% | Oct 9, 2019 | The animate-it plugin before 2.3.4 for WordPress has XSS. |
| CVE-2019-17383 | CRITICAL | 9.8 | 2.3% | Oct 9, 2019 | The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 per... |
| CVE-2019-17380 | MEDIUM | 6.1 | 0.8% | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). |
| CVE-2019-17379 | MEDIUM | 6.1 | 0.8% | Oct 9, 2019 | cPanel before 82.0.15 allows self stored XSS in the WHM SSL Storage Manager interface (SEC-527). |
| CVE-2019-17378 | MEDIUM | 6.1 | 0.8% | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in the SSL Key Delete interface (SEC-526). |
| CVE-2019-17377 | MEDIUM | 6.1 | 0.8% | Oct 9, 2019 | cPanel before 82.0.15 allows self XSS in LiveAPI example scripts (SEC-524). |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now