2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10088 | — | — | 4.8% | Aug 2, 2019 | A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. U... |
| CVE-2019-10961 | HIGH | 8.8 | 4.1% | Aug 2, 2019 | In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper va... |
| CVE-2019-9141 | CRITICAL | 9.8 | 2.4% | Aug 2, 2019 | ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers ... |
| CVE-2019-5501 | — | — | 2.0% | Aug 2, 2019 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthentica... |
| CVE-2019-5493 | — | — | 1.4% | Aug 2, 2019 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information ... |
| CVE-2019-14532 | CRITICAL | 9.8 | 2.1% | Aug 2, 2019 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/has... |
| CVE-2019-14531 | — | — | 1.8% | Aug 2, 2019 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Us... |
| CVE-2019-14235 | — | — | 3.1% | Aug 2, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain ... |
| CVE-2019-14233 | — | — | 3.2% | Aug 2, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behavio... |
| CVE-2019-14232 | HIGH | 7.5 | 3.5% | Aug 2, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If django.utils.te... |
| CVE-2019-10176 | MEDIUM | 4.2 | 0.5% | Aug 2, 2019 | A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster ... |
| CVE-2019-4275 | MEDIUM | 5.5 | 0.3% | Aug 2, 2019 | IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique cata... |
| CVE-2019-14529 | CRITICAL | 9.8 | 28.1% | Aug 2, 2019 | OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php. |
| CVE-2019-14528 | — | — | 1.0% | Aug 2, 2019 | GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code. |
| CVE-2019-10938 | CRITICAL | 9.8 | 1.5% | Aug 2, 2019 | A vulnerability has been identified in SIPROTEC 5 devices with CPU variants CP200 (All versions < V7.59), SIPROTEC 5 dev... |
| CVE-2019-10171 | HIGH | 7.5 | 1.4% | Aug 2, 2019 | It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied i... |
| CVE-2019-10168 | HIGH | 7.8 | 0.5% | Aug 2, 2019 | The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x b... |
| CVE-2019-10167 | HIGH | 7.8 | 0.5% | Aug 2, 2019 | The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emul... |
| CVE-2019-10166 | HIGH | 7.8 | 0.5% | Aug 2, 2019 | It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to u... |
| CVE-2019-14524 | HIGH | 7.8 | 1.3% | Aug 2, 2019 | An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of ... |
| CVE-2019-14523 | HIGH | 7.8 | 1.2% | Aug 2, 2019 | An issue was discovered in Schism Tracker through 20190722. There is an integer underflow via a large plen in fmt_okt_lo... |
| CVE-2019-14517 | — | — | 0.9% | Aug 1, 2019 | pandao Editor.md 1.5.0 allows XSS via the Javascript: string. |
| CVE-2019-5401 | — | — | 0.5% | Aug 1, 2019 | A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss ... |
| CVE-2019-14513 | HIGH | 7.5 | 1.7% | Aug 1, 2019 | Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that ... |
| CVE-2019-14260 | — | — | 2.8% | Aug 1, 2019 | On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injectio... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now