2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-3644HIGH7.5McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially ...
CVE-2019-3643HIGH7.5McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially ...
CVE-2019-16228HIGH7.5An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_h...
CVE-2019-16227CRITICAL9.8An issue was discovered in py-lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invali...
CVE-2019-16226HIGH7.5An issue was discovered in py-lmdb 0.97. mdb_node_del does not validate a memmove in the case of an unexpected node->mn_...
CVE-2019-16225CRITICAL9.8An issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_...
CVE-2019-16224CRITICAL9.8An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy ...
CVE-2019-8451MEDIUM6.5The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con...
CVE-2019-8450MEDIUM4.8Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 ...
CVE-2019-8449MEDIUM5.3The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username...
CVE-2019-16223MEDIUM5.4WordPress before 5.2.3 allows XSS in post previews by authenticated users.
CVE-2019-16222MEDIUM6.1WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can ...
CVE-2019-16221MEDIUM6.1WordPress before 5.2.3 allows reflected XSS in the dashboard.
CVE-2019-16220MEDIUM6.1In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou...
CVE-2019-16219MEDIUM6.1WordPress before 5.2.3 allows XSS in shortcode previews.
CVE-2019-16218MEDIUM6.1WordPress before 5.2.3 allows XSS in stored comments.
CVE-2019-16217MEDIUM6.1WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
CVE-2019-14998MEDIUM6.5The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remot...
CVE-2019-14997MEDIUM4.3The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other us...
CVE-2019-14996MEDIUM6.1The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows re...
CVE-2019-14995MEDIUM5.3The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an atta...
CVE-2019-16193MEDIUM5.4In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug...
CVE-2019-14725MEDIUM4.3In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t...
CVE-2019-14724HIGH7.5In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an ...
CVE-2019-16214MEDIUM5.7Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now