2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1924 | HIGH | 7.8 | 1.5% | Aug 7, 2019 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros... |
| CVE-2019-1918 | HIGH | 7.4 | 0.5% | Aug 7, 2019 | A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing pr... |
| CVE-2019-14763 | MEDIUM | 5.5 | 0.3% | Aug 7, 2019 | In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock ... |
| CVE-2019-1925 | HIGH | 7.8 | 1.5% | Aug 7, 2019 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros... |
| CVE-2019-1910 | HIGH | 7.4 | 0.4% | Aug 7, 2019 | A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routin... |
| CVE-2019-1895 | CRITICAL | 9.8 | 2.3% | Aug 7, 2019 | A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Sof... |
| CVE-2019-14474 | — | — | 1.9% | Aug 7, 2019 | eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, res... |
| CVE-2019-5476 | CRITICAL | 9.8 | 1.8% | Aug 7, 2019 | An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticate... |
| CVE-2019-14750 | MEDIUM | 6.1 | 11.7% | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w... |
| CVE-2019-14749 | HIGH | 8.8 | 9.6% | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex... |
| CVE-2019-14748 | MEDIUM | 5.4 | 2.7% | Aug 7, 2019 | An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl... |
| CVE-2019-14537 | — | — | 6.1% | Aug 7, 2019 | YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass. |
| CVE-2019-11653 | — | — | 0.8% | Aug 7, 2019 | Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite... |
| CVE-2019-10099 | HIGH | 7.5 | 1.3% | Aug 7, 2019 | Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encr... |
| CVE-2019-14747 | — | — | 0.8% | Aug 7, 2019 | DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter. |
| CVE-2019-14746 | — | — | 1.2% | Aug 7, 2019 | A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parame... |
| CVE-2019-14745 | HIGH | 7.8 | 4.4% | Aug 7, 2019 | In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft... |
| CVE-2019-14744 | HIGH | 7.8 | 2.6% | Aug 7, 2019 | In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with min... |
| CVE-2019-14743 | — | — | 0.5% | Aug 7, 2019 | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" ... |
| CVE-2019-14432 | — | — | 2.3% | Aug 7, 2019 | Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code ex... |
| CVE-2019-10389 | MEDIUM | 4.3 | 0.6% | Aug 7, 2019 | A missing permission check in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to... |
| CVE-2019-10388 | MEDIUM | 4.3 | 0.6% | Aug 7, 2019 | A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier all... |
| CVE-2019-10387 | MEDIUM | 6.5 | 0.9% | Aug 7, 2019 | A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnecti... |
| CVE-2019-10386 | HIGH | 8.8 | 0.9% | Aug 7, 2019 | A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescripto... |
| CVE-2019-10385 | MEDIUM | 6.5 | 1.5% | Aug 7, 2019 | Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master whe... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now