2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3644 | HIGH | 7.5 | 2.4% | Sep 11, 2019 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9517, potentially ... |
| CVE-2019-3643 | HIGH | 7.5 | 2.4% | Sep 11, 2019 | McAfee Web Gateway (MWG) earlier than 7.8.2.13 is vulnerable to a remote attacker exploiting CVE-2019-9511, potentially ... |
| CVE-2019-16228 | HIGH | 7.5 | 1.8% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_h... |
| CVE-2019-16227 | CRITICAL | 9.8 | 2.0% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invali... |
| CVE-2019-16226 | HIGH | 7.5 | 1.5% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. mdb_node_del does not validate a memmove in the case of an unexpected node->mn_... |
| CVE-2019-16225 | CRITICAL | 9.8 | 1.8% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_... |
| CVE-2019-16224 | CRITICAL | 9.8 | 1.8% | Sep 11, 2019 | An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy ... |
| CVE-2019-8451 | MEDIUM | 6.5 | 94.5% | Sep 11, 2019 | The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con... |
| CVE-2019-8450 | MEDIUM | 4.8 | 0.9% | Sep 11, 2019 | Various templates of the Optimization plugin in Jira before version 7.13.6, and from version 8.0.0 before version 8.4.0 ... |
| CVE-2019-8449 | MEDIUM | 5.3 | 84.8% | Sep 11, 2019 | The /rest/api/latest/groupuserpicker resource in Jira before version 8.4.0 allows remote attackers to enumerate username... |
| CVE-2019-16223 | MEDIUM | 5.4 | 5.2% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in post previews by authenticated users. |
| CVE-2019-16222 | MEDIUM | 6.1 | 2.2% | Sep 11, 2019 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can ... |
| CVE-2019-16221 | MEDIUM | 6.1 | 1.8% | Sep 11, 2019 | WordPress before 5.2.3 allows reflected XSS in the dashboard. |
| CVE-2019-16220 | MEDIUM | 6.1 | 2.5% | Sep 11, 2019 | In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php cou... |
| CVE-2019-16219 | MEDIUM | 6.1 | 1.9% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in shortcode previews. |
| CVE-2019-16218 | MEDIUM | 6.1 | 1.8% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in stored comments. |
| CVE-2019-16217 | MEDIUM | 6.1 | 1.5% | Sep 11, 2019 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. |
| CVE-2019-14998 | MEDIUM | 6.5 | 1.2% | Sep 11, 2019 | The Webwork action Cross-Site Request Forgery (CSRF) protection implementation in Jira before version 8.4.0 allows remot... |
| CVE-2019-14997 | MEDIUM | 4.3 | 1.2% | Sep 11, 2019 | The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other us... |
| CVE-2019-14996 | MEDIUM | 6.1 | 1.3% | Sep 11, 2019 | The FilterPickerPopup.jspa resource in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.3 allows re... |
| CVE-2019-14995 | MEDIUM | 5.3 | 3.0% | Sep 11, 2019 | The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an atta... |
| CVE-2019-16193 | MEDIUM | 5.4 | 0.6% | Sep 11, 2019 | In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack throug... |
| CVE-2019-14725 | MEDIUM | 4.3 | 1.5% | Sep 11, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to change t... |
| CVE-2019-14724 | HIGH | 7.5 | 4.4% | Sep 11, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.851, an insecure object reference allows an attacker to edit an ... |
| CVE-2019-16214 | MEDIUM | 5.7 | 1.3% | Sep 11, 2019 | Libra Core before 2019-09-03 has an erroneous regular expression for inline comments, which makes it easier for attacker... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now