2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15726 | MEDIUM | 5.3 | 1.7% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in ma... |
| CVE-2019-15725 | HIGH | 7.5 | 1.8% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API th... |
| CVE-2019-15724 | MEDIUM | 6.1 | 1.2% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerab... |
| CVE-2019-15723 | MEDIUM | 5.3 | 1.3% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests cre... |
| CVE-2019-15722 | HIGH | 7.5 | 1.9% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressi... |
| CVE-2019-15721 | MEDIUM | 5.4 | 0.8% | Sep 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintention... |
| CVE-2019-13140 | MEDIUM | 6.5 | 2.0% | Sep 16, 2019 | Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" accoun... |
| CVE-2019-0207 | HIGH | 7.5 | 3.1% | Sep 16, 2019 | Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, w... |
| CVE-2019-15950 | MEDIUM | 6.1 | 0.9% | Sep 16, 2019 | The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data. |
| CVE-2019-11184 | MEDIUM | 4.8 | 0.8% | Sep 16, 2019 | A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated u... |
| CVE-2019-11166 | MEDIUM | 6.7 | 0.3% | Sep 16, 2019 | Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authe... |
| CVE-2019-0195 | CRITICAL | 9.8 | 14.9% | Sep 16, 2019 | Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it do... |
| CVE-2019-16355 | MEDIUM | 5.5 | 0.4% | Sep 16, 2019 | The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for indivi... |
| CVE-2019-16354 | MEDIUM | 4.7 | 0.2% | Sep 16, 2019 | The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition invo... |
| CVE-2019-16353 | HIGH | 7.5 | 1.4% | Sep 16, 2019 | Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic f... |
| CVE-2019-16352 | MEDIUM | 6.5 | 1.3% | Sep 16, 2019 | ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c. |
| CVE-2019-16351 | MEDIUM | 6.5 | 1.3% | Sep 16, 2019 | ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c. |
| CVE-2019-16350 | MEDIUM | 6.5 | 1.3% | Sep 16, 2019 | ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c. |
| CVE-2019-16349 | MEDIUM | 5.5 | 0.9% | Sep 16, 2019 | Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from t... |
| CVE-2019-16348 | MEDIUM | 6.5 | 0.9% | Sep 16, 2019 | marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c. |
| CVE-2019-16347 | HIGH | 8.8 | 1.5% | Sep 16, 2019 | ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinte... |
| CVE-2019-16346 | HIGH | 8.8 | 1.6% | Sep 16, 2019 | ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinter... |
| CVE-2019-16264 | CRITICAL | 9.8 | 1.5% | Sep 16, 2019 | In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username param... |
| CVE-2019-16197 | MEDIUM | 6.1 | 3.0% | Sep 16, 2019 | In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document ... |
| CVE-2019-16170 | HIGH | 7.1 | 1.0% | Sep 16, 2019 | An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x befor... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now