2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11654 | HIGH | 7.5 | 2.6% | Aug 23, 2019 | Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerab... |
| CVE-2019-15531 | MEDIUM | 6.5 | 1.7% | Aug 23, 2019 | GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/d... |
| CVE-2019-15530 | — | — | 4.3% | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo... |
| CVE-2019-15529 | — | — | 7.7% | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo... |
| CVE-2019-15528 | — | — | 4.1% | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo... |
| CVE-2019-15527 | — | — | 4.1% | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo... |
| CVE-2019-15526 | — | — | 4.1% | Aug 23, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware V1.0.2B05. There is a command injection in HNAP1 (explo... |
| CVE-2019-13014 | MEDIUM | 5.5 | 0.4% | Aug 23, 2019 | Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the operating system may have m... |
| CVE-2019-13013 | MEDIUM | 5.5 | 0.3% | Aug 23, 2019 | Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. T... |
| CVE-2019-10751 | — | — | 2.0% | Aug 23, 2019 | All versions of the HTTPie package prior to version 1.0.3 are vulnerable to Open Redirect that allows an attacker to wri... |
| CVE-2019-10750 | CRITICAL | 9.8 | 1.7% | Aug 23, 2019 | deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into add... |
| CVE-2019-10747 | CRITICAL | 9.8 | 2.5% | Aug 23, 2019 | set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked in... |
| CVE-2019-10746 | CRITICAL | 9.8 | 3.5% | Aug 23, 2019 | mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep coul... |
| CVE-2019-15525 | — | — | 0.8% | Aug 23, 2019 | There is Missing SSL Certificate Validation in the pw3270 terminal emulator before version 5.1. |
| CVE-2019-15520 | — | — | 1.9% | Aug 23, 2019 | comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory. |
| CVE-2019-15519 | — | — | 3.0% | Aug 23, 2019 | Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. |
| CVE-2019-15518 | — | — | 2.0% | Aug 23, 2019 | Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. |
| CVE-2019-15517 | — | — | 0.7% | Aug 23, 2019 | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. |
| CVE-2019-15516 | — | — | 2.2% | Aug 23, 2019 | Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply remove... |
| CVE-2019-8447 | — | — | 0.7% | Aug 23, 2019 | The ServiceExecutor resource in Jira before version 8.3.2 allows remote attackers to trigger the creation of export file... |
| CVE-2019-8446 | MEDIUM | 5.3 | 17.5% | Aug 23, 2019 | The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via... |
| CVE-2019-8445 | MEDIUM | 5.3 | 2.7% | Aug 23, 2019 | Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote a... |
| CVE-2019-8444 | MEDIUM | 5.4 | 0.9% | Aug 23, 2019 | The wikirenderer component in Jira before version 7.13.6, and from version 8.0.0 before version 8.3.2 allows remote atta... |
| CVE-2019-14999 | — | — | 0.6% | Aug 23, 2019 | The Uninstall REST endpoint in Atlassian Universal Plugin Manager before version 2.22.19, from version 3.0.0 before vers... |
| CVE-2019-13423 | HIGH | 8.8 | 0.7% | Aug 23, 2019 | Search Guard Kibana Plugin versions before 5.6.8-7 and before 6.x.y-12 had an issue that an authenticated Kibana user co... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now