2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5452 | LOW | 2.4 | 0.4% | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.6.2 causes leaking of thumbnails when requesting ... |
| CVE-2019-5451 | MEDIUM | 4.6 | 0.4% | Jul 30, 2019 | Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly op... |
| CVE-2019-5450 | MEDIUM | 6.8 | 0.5% | Jul 30, 2019 | Improper sanitization of HTML in directory names in the Nextcloud Android app prior to version 3.7.0 allowed to style th... |
| CVE-2019-5449 | MEDIUM | 4.3 | 0.9% | Jul 30, 2019 | A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or mo... |
| CVE-2019-5448 | HIGH | 8.1 | 0.7% | Jul 30, 2019 | Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypte... |
| CVE-2019-13026 | — | — | 1.4% | Jul 30, 2019 | OXID eShop 6.0.x before 6.0.5 and 6.1.x before 6.1.4 allows SQL Injection via a crafted URL, leading to full access by a... |
| CVE-2019-14383 | MEDIUM | 6.5 | 1.3% | Jul 30, 2019 | J2B in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
| CVE-2019-14382 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | DSM in libopenmpt before 0.4.2 allows an assertion failure during file parsing with debug STLs. |
| CVE-2019-14380 | MEDIUM | 6.5 | 0.9% | Jul 30, 2019 | libopenmpt before 0.4.5 allows a crash during playback due to an out-of-bounds read in XM and MT2 files. |
| CVE-2019-14313 | CRITICAL | 9.8 | 4.5% | Jul 30, 2019 | A SQL injection vulnerability exists in the 10Web Photo Gallery plugin before 1.5.31 for WordPress. Successful exploitat... |
| CVE-2019-14242 | — | — | 0.6% | Jul 30, 2019 | An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.... |
| CVE-2019-1552 | — | — | 0.7% | Jul 30, 2019 | OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used f... |
| CVE-2019-14318 | — | — | 3.2% | Jul 30, 2019 | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote a... |
| CVE-2019-11202 | — | — | 1.6% | Jul 30, 2019 | An issue was discovered that affects the following versions of Rancher: v2.0.0 through v2.0.13, v2.1.0 through v2.1.8, a... |
| CVE-2019-10142 | HIGH | 7.1 | 0.4% | Jul 30, 2019 | A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excludi... |
| CVE-2019-10141 | HIGH | 8.3 | 2.5% | Jul 30, 2019 | A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A S... |
| CVE-2019-10138 | HIGH | 8.8 | 1.0% | Jul 30, 2019 | A flaw was discovered in the python-novajoin plugin, all versions up to, excluding 1.1.1, for Red Hat OpenStack Platform... |
| CVE-2019-10130 | MEDIUM | 4.3 | 1.1% | Jul 30, 2019 | A vulnerability was found in PostgreSQL versions 11.x up to excluding 11.3, 10.x up to excluding 10.8, 9.6.x up to, excl... |
| CVE-2019-10129 | MEDIUM | 6.5 | 1.6% | Jul 30, 2019 | A vulnerability was found in postgresql versions 11.x prior to 11.3. Using a purpose-crafted insert to a partitioned tab... |
| CVE-2019-14414 | — | — | 0.3% | Jul 30, 2019 | In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). |
| CVE-2019-14413 | — | — | 0.6% | Jul 30, 2019 | cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). |
| CVE-2019-14412 | — | — | 0.4% | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). |
| CVE-2019-14411 | — | — | 0.8% | Jul 30, 2019 | cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). |
| CVE-2019-14410 | — | — | 0.4% | Jul 30, 2019 | Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). |
| CVE-2019-14409 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now