2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13638 | — | — | 4.5% | Jul 26, 2019 | GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch fil... |
| CVE-2019-13565 | HIGH | 7.5 | 5.0% | Jul 26, 2019 | An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relyin... |
| CVE-2019-13387 | MEDIUM | 6.1 | 2.2% | Jul 26, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, Reflected XSS in filemanager2.php (parameter fm_current_dir... |
| CVE-2019-13386 | HIGH | 8.8 | 2.8% | Jul 26, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, a hidden action=9 feature in filemanager2.php allows attack... |
| CVE-2019-13385 | MEDIUM | 4.3 | 2.0% | Jul 26, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.840, File and Directory Information Exposure in filemanager allo... |
| CVE-2019-13382 | — | — | 1.6% | Jul 26, 2019 | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA... |
| CVE-2019-13057 | MEDIUM | 4.9 | 3.2% | Jul 26, 2019 | An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (databas... |
| CVE-2019-14282 | — | — | 3.1% | Jul 26, 2019 | The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a... |
| CVE-2019-14281 | — | — | 3.1% | Jul 26, 2019 | The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third ... |
| CVE-2019-14280 | — | — | 8.0% | Jul 26, 2019 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe... |
| CVE-2019-14277 | CRITICAL | 9.8 | 7.3% | Jul 26, 2019 | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticat... |
| CVE-2019-14275 | MEDIUM | 5.5 | 1.2% | Jul 26, 2019 | Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c. |
| CVE-2019-14274 | MEDIUM | 5.5 | 1.6% | Jul 26, 2019 | MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. |
| CVE-2019-5607 | HIGH | 7.8 | 0.5% | Jul 26, 2019 | In FreeBSD 12.0-STABLE before r350222, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350223, 11.3-RELEASE bef... |
| CVE-2019-5606 | HIGH | 7.8 | 0.6% | Jul 26, 2019 | In FreeBSD 12.0-STABLE before r349805, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r349806, 11.3-RELEASE bef... |
| CVE-2019-5605 | MEDIUM | 6.5 | 2.3% | Jul 26, 2019 | In FreeBSD 11.3-STABLE before r350217, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, du... |
| CVE-2019-5604 | CRITICAL | 9.6 | 3.1% | Jul 26, 2019 | In FreeBSD 12.0-STABLE before r350246, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350247, 11.3-RELEASE bef... |
| CVE-2019-5603 | HIGH | 7.8 | 0.6% | Jul 26, 2019 | In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE bef... |
| CVE-2019-10976 | — | — | 1.0% | Jul 26, 2019 | Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the ... |
| CVE-2019-10974 | MEDIUM | 5.5 | 0.3% | Jul 26, 2019 | NREL EnergyPlus, Versions 8.6.0 and possibly prior versions, The application fails to prevent an exception handler from ... |
| CVE-2019-10972 | MEDIUM | 5.5 | 0.9% | Jul 26, 2019 | Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker prov... |
| CVE-2019-10744 | CRITICAL | 9.1 | 5.0% | Jul 26, 2019 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked ... |
| CVE-2019-1010147 | — | — | 0.7% | Jul 26, 2019 | Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. Th... |
| CVE-2019-0202 | — | — | 2.0% | Jul 26, 2019 | The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In ... |
| CVE-2019-11922 | — | — | 1.4% | Jul 25, 2019 | A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to wr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now