2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13327 | HIGH | 7.8 | 3.9% | Oct 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207... |
| CVE-2019-13326 | HIGH | 7.8 | 3.9% | Oct 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207... |
| CVE-2019-13325 | HIGH | 7.8 | 3.9% | Oct 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2019-13324 | HIGH | 7.8 | 3.9% | Oct 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2019-13323 | HIGH | 7.8 | 3.9% | Oct 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6... |
| CVE-2019-11932 | HIGH | 8.8 | 44.5% | Oct 3, 2019 | A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version ... |
| CVE-2019-16198 | MEDIUM | 6.5 | 1.6% | Oct 3, 2019 | KSLabs KSWEB 3.93 allows ../ directory traversal, as demonstrated by the hostFile parameter. |
| CVE-2019-15766 | HIGH | 8.8 | 3.1% | Oct 3, 2019 | The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POS... |
| CVE-2019-17110 | — | — | — | Oct 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-10223. Reason: This candidate is a duplicate of ... |
| CVE-2019-16328 | HIGH | 7.5 | 13.0% | Oct 3, 2019 | In RPyC 4.1.x through 4.1.1, a remote attacker can dynamically modify object attributes to construct a remote procedure ... |
| CVE-2019-16931 | MEDIUM | 6.1 | 3.3% | Oct 3, 2019 | A stored XSS vulnerability in the Visualizer plugin 3.3.0 for WordPress allows an unauthenticated attacker to execute ar... |
| CVE-2019-16866 | HIGH | 7.5 | 3.5% | Oct 3, 2019 | Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIF... |
| CVE-2019-15165 | MEDIUM | 5.3 | 2.8% | Oct 3, 2019 | sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. |
| CVE-2019-15164 | MEDIUM | 5.3 | 2.9% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source. |
| CVE-2019-15163 | HIGH | 7.5 | 4.4% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daem... |
| CVE-2019-15162 | MEDIUM | 5.3 | 1.8% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which... |
| CVE-2019-15161 | MEDIUM | 5.3 | 2.8% | Oct 3, 2019 | rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open u... |
| CVE-2019-15166 | HIGH | 7.5 | 5.0% | Oct 3, 2019 | lmp_print_data_link_subobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks. |
| CVE-2019-4441 | MEDIUM | 5.3 | 1.8% | Oct 3, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0, and Liberty could allow a remote attacker to obtain sensitive infor... |
| CVE-2019-4422 | HIGH | 8.8 | 1.7% | Oct 3, 2019 | IBM Security Guardium 9.0, 9.5, and 10.6 are vulnerable to a privilege escalation which could allow an authenticated use... |
| CVE-2019-3834 | HIGH | 7.3 | 1.0% | Oct 3, 2019 | It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows atta... |
| CVE-2019-15809 | MEDIUM | 4.7 | 0.5% | Oct 3, 2019 | Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timi... |
| CVE-2019-13629 | MEDIUM | 5.9 | 1.2% | Oct 3, 2019 | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remot... |
| CVE-2019-13628 | MEDIUM | 4.7 | 0.4% | Oct 3, 2019 | wolfSSL and wolfCrypt 4.0.0 and earlier (when configured without --enable-fpecc, --enable-sp, or --enable-sp-math) conta... |
| CVE-2019-11651 | MEDIUM | 6.1 | 0.8% | Oct 2, 2019 | Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now