2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16748 | CRITICAL | 9.8 | 1.2% | Sep 24, 2019 | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while han... |
| CVE-2019-16746 | CRITICAL | 9.8 | 12.7% | Sep 24, 2019 | An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of va... |
| CVE-2019-16729 | HIGH | 7.8 | 0.4% | Sep 24, 2019 | pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could all... |
| CVE-2019-16728 | MEDIUM | 6.1 | 1.7% | Sep 24, 2019 | DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demo... |
| CVE-2019-10755 | MEDIUM | 4.9 | 1.1% | Sep 23, 2019 | The SAML identifier generated within SAML2Utils.java was found to make use of the apache commons-lang3 RandomStringUtils... |
| CVE-2019-10754 | HIGH | 8.1 | 1.8% | Sep 23, 2019 | Multiple classes used within Apereo CAS before release 6.1.0-RC5 makes use of apache commons-lang3 RandomStringUtils for... |
| CVE-2019-1367 | HIGH | 7.5 | 52.7% | Sep 23, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-1255 | HIGH | 7.5 | 3.9% | Sep 23, 2019 | A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denia... |
| CVE-2019-11277 | HIGH | 8.1 | 1.7% | Sep 23, 2019 | Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP ... |
| CVE-2019-15635 | MEDIUM | 4.9 | 1.6% | Sep 23, 2019 | An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An... |
| CVE-2019-16377 | CRITICAL | 9.8 | 2.6% | Sep 23, 2019 | The makandra consul gem through 1.0.2 for Ruby has Incorrect Access Control. |
| CVE-2019-12407 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10996 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10990 | MEDIUM | 6.5 | 1.3% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, uses a hard-coded password to... |
| CVE-2019-10984 | HIGH | 7.8 | 1.0% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10978 | HIGH | 7.8 | 0.9% | Sep 23, 2019 | Red Lion Controls Crimson, version 3.0 and prior and version 3.1 prior to release 3112.00, allow multiple vulnerabilitie... |
| CVE-2019-10090 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-16723 | MEDIUM | 4.3 | 1.5% | Sep 23, 2019 | In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_jso... |
| CVE-2019-16518 | MEDIUM | 4.3 | 0.6% | Sep 23, 2019 | An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an... |
| CVE-2019-13063 | HIGH | 7.5 | 27.2% | Sep 23, 2019 | Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc... |
| CVE-2019-12404 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10089 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-10087 | MEDIUM | 6.1 | 2.9% | Sep 23, 2019 | On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerabilit... |
| CVE-2019-3416 | CRITICAL | 9.8 | 1.1% | Sep 23, 2019 | All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to inp... |
| CVE-2019-16722 | CRITICAL | 9.8 | 3.1% | Sep 23, 2019 | ZZZCMS zzzphp v1.7.2 has an insufficient protection mechanism against PHP Code Execution, because passthru bypasses an s... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now