2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16162 | HIGH | 7.5 | 1.8% | Sep 9, 2019 | Onigmo through 6.2.0 has an out-of-bounds read in parse_char_class because of missing codepoint validation in regenc.c. |
| CVE-2019-16161 | HIGH | 7.5 | 2.1% | Sep 9, 2019 | Onigmo through 6.2.0 has a NULL pointer dereference in onig_error_code_to_str because of fetch_token in regparse.c. |
| CVE-2019-12405 | CRITICAL | 9.8 | 3.5% | Sep 9, 2019 | Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in t... |
| CVE-2019-16159 | HIGH | 7.5 | 3.2% | Sep 9, 2019 | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon... |
| CVE-2019-12465 | HIGH | 8.1 | 1.2% | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. A SQL injection flaw was identified in the ajax_rulesuggest.php file where t... |
| CVE-2019-12464 | HIGH | 7.5 | 2.2% | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. An authenticated user can perform a directory traversal attack against the /... |
| CVE-2019-12463 | HIGH | 8.8 | 1.4% | Sep 9, 2019 | An issue was discovered in LibreNMS 1.50.1. The scripts that handle graphing options (includes/html/graphs/common.inc.ph... |
| CVE-2019-10671 | HIGH | 8.8 | 1.3% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. It does not parameterize all user supplied input within database queri... |
| CVE-2019-10670 | MEDIUM | 6.1 | 0.8% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for... |
| CVE-2019-16148 | MEDIUM | 6.1 | 0.8% | Sep 9, 2019 | Sakai through 12.6 allows XSS via a chat user name. |
| CVE-2019-16146 | MEDIUM | 4.8 | 0.7% | Sep 9, 2019 | Gophish through 0.8.0 allows XSS via a username. |
| CVE-2019-16114 | CRITICAL | 9.8 | 4.8% | Sep 9, 2019 | In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted databas... |
| CVE-2019-15895 | HIGH | 7.5 | 1.7% | Sep 9, 2019 | search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes. |
| CVE-2019-15639 | HIGH | 7.5 | 21.9% | Sep 9, 2019 | main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a ... |
| CVE-2019-10669 | HIGH | 7.2 | 80.7% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev... |
| CVE-2019-10668 | CRITICAL | 9.1 | 1.6% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not en... |
| CVE-2019-10667 | MEDIUM | 5.3 | 1.2% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exac... |
| CVE-2019-10666 | HIGH | 8.1 | 1.2% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. Several of the scripts perform dynamic script inclusion via the includ... |
| CVE-2019-10665 | CRITICAL | 9.8 | 1.5% | Sep 9, 2019 | An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/com... |
| CVE-2019-16144 | HIGH | 7.5 | 1.6% | Sep 9, 2019 | An issue was discovered in the generator crate before 0.6.18 for Rust. Uninitialized memory is used by Scope, done, and ... |
| CVE-2019-16143 | CRITICAL | 9.8 | 0.9% | Sep 9, 2019 | An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HM... |
| CVE-2019-16142 | CRITICAL | 9.8 | 1.8% | Sep 9, 2019 | An issue was discovered in the renderdoc crate before 0.5.0 for Rust. Multiple exposed methods take self by immutable re... |
| CVE-2019-16141 | HIGH | 7.5 | 1.6% | Sep 9, 2019 | An issue was discovered in the once_cell crate before 1.0.1 for Rust. There is a panic during initialization of Lazy. |
| CVE-2019-16140 | CRITICAL | 9.8 | 1.6% | Sep 9, 2019 | An issue was discovered in the chttp crate before 0.1.3 for Rust. There is a use-after-free during buffer conversion. |
| CVE-2019-16139 | CRITICAL | 9.8 | 1.9% | Sep 9, 2019 | An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now