2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3728 | HIGH | 7.5 | 2.4% | Sep 30, 2019 | RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Editi... |
| CVE-2019-16760 | HIGH | 7.5 | 1.3% | Sep 30, 2019 | Cargo prior to Rust 1.26.0 may download the wrong dependency if your package.toml file uses the `package` configuration ... |
| CVE-2019-17051 | HIGH | 7.8 | 1.6% | Sep 30, 2019 | Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attach... |
| CVE-2019-13124 | HIGH | 7.5 | 1.3% | Sep 30, 2019 | Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack ... |
| CVE-2019-13123 | HIGH | 7.5 | 1.3% | Sep 30, 2019 | Foxit Reader 9.6.0.25114 and earlier has two unique RecursiveCall bugs involving 3 functions exhausting available stack ... |
| CVE-2019-17050 | HIGH | 7.2 | 1.3% | Sep 30, 2019 | An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass ... |
| CVE-2019-17049 | HIGH | 7.5 | 1.1% | Sep 30, 2019 | NETGEAR SRX5308 4.3.5-3 devices allow SQL Injection, as exploited in the wild in September 2019 to add a new user accoun... |
| CVE-2019-16276 | HIGH | 7.5 | 5.2% | Sep 30, 2019 | Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. |
| CVE-2019-13467 | MEDIUM | 5.9 | 1.5% | Sep 30, 2019 | Description: Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 applications are pote... |
| CVE-2019-13466 | HIGH | 7.5 | 0.7% | Sep 30, 2019 | Western Digital SSD Dashboard before 2.5.1.0 and SanDisk SSD Dashboard before 2.5.1.0 have Incorrect Access Control. The... |
| CVE-2019-15810 | MEDIUM | 6.1 | 0.9% | Sep 30, 2019 | Insufficient sanitization during device search in Netdisco 2.042010 allows for reflected XSS via manipulation of a URL p... |
| CVE-2019-4423 | MEDIUM | 5.3 | 2.7% | Sep 30, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 could allow a remote attacker to traverse directories on the system. A... |
| CVE-2019-4305 | MEDIUM | 5.3 | 1.5% | Sep 30, 2019 | IBM WebSphere Application Server Liberty could allow a remote attacker to obtain sensitive information caused by the imp... |
| CVE-2019-4304 | MEDIUM | 6.3 | 1.1% | Sep 30, 2019 | IBM WebSphere Application Server - Liberty could allow a remote attacker to bypass security restrictions caused by impro... |
| CVE-2019-4280 | MEDIUM | 5.3 | 0.8% | Sep 30, 2019 | IBM Sterling File Gateway 2.2.0.0 through 6.0.1.0 displays sensitive information in HTTP requests which could be used in... |
| CVE-2019-4115 | MEDIUM | 5.4 | 0.7% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin API is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2019-4112 | LOW | 3.3 | 0.3% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin Console allows web pages to be stored locally which can be read by another user on... |
| CVE-2019-4109 | MEDIUM | 6.1 | 1.3% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin Console could allow a remote attacker to hijack the clicking action of the victim.... |
| CVE-2019-4106 | MEDIUM | 4.8 | 0.7% | Sep 30, 2019 | IBM WebSphere eXtreme Scale 8.6 Admin Console is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2019-2341 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow when the audio buffer size provided by user is larger than the maximum allowable audio buffer size. in S... |
| CVE-2019-2333 | HIGH | 7.8 | 0.2% | Sep 30, 2019 | Buffer overflow due to improper validation of buffer size while IPA driver processing to perform read operation in Snapd... |
| CVE-2019-2294 | CRITICAL | 9.8 | 0.9% | Sep 30, 2019 | Usage of hard-coded magic number for calculating heap guard bytes can allow users to corrupt heap blocks without heap al... |
| CVE-2019-2284 | HIGH | 7 | 0.1% | Sep 30, 2019 | Possible use-after-free issue due to a race condition while calling camera ioctl concurrently in Snapdragon Compute, Sna... |
| CVE-2019-2252 | CRITICAL | 9.8 | 1.2% | Sep 30, 2019 | Classic buffer overflow vulnerability while playing the specific video whose Decode picture buffer size is more than 16 ... |
| CVE-2019-16932 | CRITICAL | 10 | 39.1% | Sep 30, 2019 | A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-d... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now