2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15726MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in ma...
CVE-2019-15725HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API th...
CVE-2019-15724MEDIUM6.1An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerab...
CVE-2019-15723MEDIUM5.3An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests cre...
CVE-2019-15722HIGH7.5An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressi...
CVE-2019-15721MEDIUM5.4An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintention...
CVE-2019-13140MEDIUM6.5Inteno EG200 EG200-WU7P1U_ADAMO3.16.4-190226_1650 routers have a JUCI ACL misconfiguration that allows the "user" accoun...
CVE-2019-0207HIGH7.5Tapestry processes assets `/assets/ctx` using classes chain `StaticFilesFilter -> AssetDispatcher -> ContextResource`, w...
CVE-2019-15950MEDIUM6.1The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
CVE-2019-11184MEDIUM4.8A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated u...
CVE-2019-11166MEDIUM6.7Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authe...
CVE-2019-0195CRITICAL9.8Manipulating classpath asset file URLs, an attacker could guess the path to a known file in the classpath and have it do...
CVE-2019-16355MEDIUM5.5The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for indivi...
CVE-2019-16354MEDIUM4.7The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition invo...
CVE-2019-16353HIGH7.5Emerson GE Automation Proficy Machine Edition 8.0 allows an access violation and application crash via crafted traffic f...
CVE-2019-16352MEDIUM6.5ffjpeg before 2019-08-21 has a heap-based buffer overflow in jfif_load() at jfif.c.
CVE-2019-16351MEDIUM6.5ffjpeg before 2019-08-18 has a NULL pointer dereference in huffman_decode_step() at huffman.c.
CVE-2019-16350MEDIUM6.5ffjpeg before 2019-08-18 has a NULL pointer dereference in idct2d8x8() at dct.c.
CVE-2019-16349MEDIUM5.5Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from t...
CVE-2019-16348MEDIUM6.5marc-q libwav through 2017-04-20 has a NULL pointer dereference in gain_file() at wav_gain.c.
CVE-2019-16347HIGH8.8ngiflib 0.4 has a heap-based buffer overflow in WritePixels() in ngiflib.c when called from DecodeGifImg, because deinte...
CVE-2019-16346HIGH8.8ngiflib 0.4 has a heap-based buffer overflow in WritePixel() in ngiflib.c when called from DecodeGifImg, because deinter...
CVE-2019-16264CRITICAL9.8In Escuela de Gestion Publica Plurinacional (EGPP) Sistema Integrado de Gestion Academica (GESAC) v1, the username param...
CVE-2019-16197MEDIUM6.1In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document ...
CVE-2019-16170HIGH7.1An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x befor...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now