2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1020001 | — | — | 2.3% | Jul 29, 2019 | yard before 0.9.20 allows path traversal. |
| CVE-2019-14379 | CRITICAL | 9.8 | 8.0% | Jul 29, 2019 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (becau... |
| CVE-2019-14378 | — | — | 16.7% | Jul 29, 2019 | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a cas... |
| CVE-2019-14373 | — | — | 1.0% | Jul 28, 2019 | An issue was discovered in image_save_png in image/image-png.cpp in Free Lossless Image Format (FLIF) 0.3. Attackers can... |
| CVE-2019-14372 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | In Libav 12.3, there is an infinite loop in the function wv_read_block_header() in the file wvdec.c. |
| CVE-2019-14371 | — | — | 1.0% | Jul 28, 2019 | An issue was discovered in Libav 12.3. There is an infinite loop in the function mov_probe in the file libavformat/mov.c... |
| CVE-2019-14370 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | In Exiv2 0.27.99.0, there is an out-of-bounds read in Exiv2::MrwImage::readMetadata() in mrwimage.cpp. It could result i... |
| CVE-2019-14369 | MEDIUM | 6.5 | 1.1% | Jul 28, 2019 | Exiv2::PngImage::readMetadata() in pngimage.cpp in Exiv2 0.27.99.0 allows attackers to cause a denial of service (heap-b... |
| CVE-2019-14368 | — | — | 1.0% | Jul 28, 2019 | Exiv2 0.27.99.0 has a heap-based buffer over-read in Exiv2::RafImage::readMetadata() in rafimage.cpp. |
| CVE-2019-14364 | MEDIUM | 6.1 | 1.3% | Jul 28, 2019 | An XSS vulnerability in the "Email Subscribers & Newsletters" plugin 4.1.6 for WordPress allows an attacker to inject ma... |
| CVE-2019-14363 | — | — | 3.1% | Jul 28, 2019 | A stack-based buffer overflow in the upnpd binary running on NETGEAR WNDR3400v3 routers with firmware version 1.0.1.18_1... |
| CVE-2019-14362 | — | — | 2.1% | Jul 28, 2019 | Openbravo ERP before 3.0PR19Q1.3 is affected by Directory Traversal. This vulnerability could allow remote authenticated... |
| CVE-2019-14352 | — | — | 1.0% | Jul 28, 2019 | In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists, as demonstrated by jw/web/userview/crm... |
| CVE-2019-14351 | — | — | 1.3% | Jul 28, 2019 | EspoCRM 5.6.4 is vulnerable to user password hash enumeration. A malicious authenticated attacker can brute-force a user... |
| CVE-2019-14350 | — | — | 0.9% | Jul 28, 2019 | EspoCRM 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the Knowledge base. A malic... |
| CVE-2019-14349 | — | — | 0.9% | Jul 28, 2019 | EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document... |
| CVE-2019-14331 | — | — | 1.3% | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Cr... |
| CVE-2019-14330 | — | — | 1.3% | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. Stored XSS exists due to lack of filtration of user-supplied data in Cr... |
| CVE-2019-14329 | — | — | 1.3% | Jul 28, 2019 | An issue was discovered in EspoCRM before 5.6.6. There is stored XSS due to lack of filtration of user-supplied data in ... |
| CVE-2019-14328 | — | — | 3.1% | Jul 28, 2019 | The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. |
| CVE-2019-14323 | HIGH | 7.5 | 1.7% | Jul 28, 2019 | SSDP Responder 1.x through 1.5 mishandles incoming network messages, leading to a stack-based buffer overflow by 1 byte.... |
| CVE-2019-14322 | HIGH | 7.5 | 55.5% | Jul 28, 2019 | In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames. |
| CVE-2019-14315 | MEDIUM | 6.1 | 1.2% | Jul 28, 2019 | A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier ... |
| CVE-2019-14298 | — | — | 0.7% | Jul 27, 2019 | Veeam ONE Reporter 9.5.0.3201 allows XSS via a crafted Description(config) field to addDashboard or editDashboard in Com... |
| CVE-2019-14297 | — | — | 0.7% | Jul 27, 2019 | Veeam ONE Reporter 9.5.0.3201 allows XSS via the Add/Edit Widget with a crafted Caption field to setDashboardWidget in C... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now