2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14408 | — | — | 0.6% | Jul 30, 2019 | cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). |
| CVE-2019-14407 | — | — | 0.7% | Jul 30, 2019 | cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). |
| CVE-2019-14406 | — | — | 0.6% | Jul 30, 2019 | cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). |
| CVE-2019-14405 | — | — | 1.5% | Jul 30, 2019 | cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). |
| CVE-2019-14404 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_s... |
| CVE-2019-14403 | — | — | 0.7% | Jul 30, 2019 | cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). |
| CVE-2019-14402 | — | — | 0.3% | Jul 30, 2019 | cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481). |
| CVE-2019-14401 | — | — | 1.5% | Jul 30, 2019 | cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480). |
| CVE-2019-14400 | — | — | 0.4% | Jul 30, 2019 | cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479). |
| CVE-2019-14399 | — | — | 0.3% | Jul 30, 2019 | The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root ac... |
| CVE-2019-14398 | — | — | 1.5% | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498). |
| CVE-2019-14397 | — | — | 0.8% | Jul 30, 2019 | cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496). |
| CVE-2019-14396 | — | — | 0.3% | Jul 30, 2019 | API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495). |
| CVE-2019-14395 | — | — | 0.3% | Jul 30, 2019 | cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). |
| CVE-2019-14394 | — | — | 0.2% | Jul 30, 2019 | cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for... |
| CVE-2019-14393 | — | — | 0.4% | Jul 30, 2019 | cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp ... |
| CVE-2019-4456 | HIGH | 7.1 | 1.9% | Jul 30, 2019 | IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XX... |
| CVE-2019-4285 | MEDIUM | 5.4 | 1.1% | Jul 30, 2019 | IBM WebSphere Application Server - Liberty Admin Center could allow a remote attacker to hijack the clicking action of t... |
| CVE-2019-4062 | HIGH | 7.1 | 1.6% | Jul 30, 2019 | IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack w... |
| CVE-2019-14392 | — | — | 1.8% | Jul 30, 2019 | cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). |
| CVE-2019-11775 | HIGH | 7.4 | 1.5% | Jul 30, 2019 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is ... |
| CVE-2019-14444 | MEDIUM | 5.5 | 1.5% | Jul 30, 2019 | apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a writ... |
| CVE-2019-14443 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | An issue was discovered in Libav 12.3. Division by zero in range_decode_culshift in libavcodec/apedec.c allows remote at... |
| CVE-2019-14442 | MEDIUM | 6.5 | 1.0% | Jul 30, 2019 | In mpc8_read_header in libavformat/mpc8.c in Libav 12.3, an input file can result in an avio_seek infinite loop and hang... |
| CVE-2019-14441 | MEDIUM | 6.5 | 1.2% | Jul 30, 2019 | An issue was discovered in Libav 12.3. An access violation allows remote attackers to cause a denial of service (applica... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now