2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15546 | — | — | 1.1% | Aug 26, 2019 | An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabi... |
| CVE-2019-15545 | — | — | 0.8% | Aug 26, 2019 | An issue was discovered in the libp2p-core crate before 0.8.1 for Rust. Attackers can spoof ed25519 signatures. |
| CVE-2019-15544 | HIGH | 7.5 | 3.8% | Aug 26, 2019 | An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve c... |
| CVE-2019-15543 | — | — | 1.6% | Aug 26, 2019 | An issue was discovered in the slice-deque crate before 0.2.0 for Rust. There is memory corruption in certain allocation... |
| CVE-2019-15542 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree... |
| CVE-2019-15533 | — | — | 1.4% | Aug 26, 2019 | XENFCoreSharp before 2019-07-16 allows SQL injection in web/verify.php. |
| CVE-2019-15515 | — | — | 0.6% | Aug 26, 2019 | Discourse 2.3.2 sends the CSRF token in the query string. |
| CVE-2019-15503 | — | — | 2.4% | Aug 26, 2019 | cgi-cpn/xcoding/prontus_videocut.cgi in AltaVoz Prontus (aka ProntusCMS) through 12.0.3.0 has "Improper Neutralization o... |
| CVE-2019-13020 | — | — | 1.1% | Aug 26, 2019 | The fetch API in Tightrope Media Carousel before 7.1.3 has CarouselAPI/v0/fetch?url= SSRF. This has two potential areas ... |
| CVE-2019-12532 | HIGH | 7.8 | 0.4% | Aug 26, 2019 | Improper access control in the Insyde software tools may allow an authenticated user to potentially enable escalation of... |
| CVE-2019-15640 | — | — | 1.2% | Aug 26, 2019 | Limesurvey before 3.17.10 does not validate both the MIME type and file extension of an image. |
| CVE-2019-15637 | HIGH | 8.1 | 14.3% | Aug 26, 2019 | Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat... |
| CVE-2019-15558 | — | — | 1.4% | Aug 26, 2019 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, a... |
| CVE-2019-15557 | — | — | 1.5% | Aug 26, 2019 | XM^online 2 User Account and Authentication server 1.0.0 allows SQL injection via a tenant key. |
| CVE-2019-15555 | — | — | 1.4% | Aug 26, 2019 | FredReinink Wellness-app before 2019-06-19 allows SQL injection, related to dietTrack.php, exerciseGenerator.php, fitnes... |
| CVE-2019-15549 | — | — | 1.4% | Aug 26, 2019 | An issue was discovered in the asn1_der crate before 0.6.2 for Rust. Attackers can trigger memory exhaustion by supplyin... |
| CVE-2019-15560 | — | — | 1.4% | Aug 26, 2019 | The Reviews Module before 2019-06-14 for OpenSource Table allows SQL injection in database/index.js. |
| CVE-2019-15559 | — | — | 1.4% | Aug 26, 2019 | DianoxDragon Hawn before 2019-07-10 allows SQL injection. |
| CVE-2019-4513 | HIGH | 8.2 | 2.8% | Aug 26, 2019 | IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) ... |
| CVE-2019-4448 | HIGH | 7.8 | 0.3% | Aug 26, 2019 | IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum an... |
| CVE-2019-4447 | HIGH | 7.8 | 0.4% | Aug 26, 2019 | IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_de... |
| CVE-2019-4169 | CRITICAL | 9.1 | 1.7% | Aug 26, 2019 | IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC... |
| CVE-2019-15574 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows serviceID SQL injection in accountmanagement.php. |
| CVE-2019-15573 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows SQL injection in tankyou.php. |
| CVE-2019-15572 | — | — | 1.4% | Aug 26, 2019 | Gesior-AAC before 2019-05-01 allows ServiceCategoryID SQL injection in shop.php. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now