2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13989 | HIGH | 7.8 | 1.0% | Jul 19, 2019 | dpic 2019.06.20 has a Stack-based Buffer Overflow in the wfloat() function in main.c. |
| CVE-2019-12821 | — | — | 0.9% | Jul 19, 2019 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the a... |
| CVE-2019-12820 | — | — | 0.5% | Jul 19, 2019 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app s... |
| CVE-2019-12945 | — | — | — | Jul 19, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-12453 | — | — | 1.0% | Jul 19, 2019 | In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation. |
| CVE-2019-11553 | — | — | 1.0% | Jul 19, 2019 | In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage u... |
| CVE-2019-1010241 | MEDIUM | 6.5 | 1.5% | Jul 19, 2019 | Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The ... |
| CVE-2019-1010239 | HIGH | 7.5 | 2.4% | Jul 19, 2019 | DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null d... |
| CVE-2019-1010238 | CRITICAL | 9.8 | 6.3% | Jul 19, 2019 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to... |
| CVE-2019-12193 | — | — | 1.5% | Jul 19, 2019 | H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter. |
| CVE-2019-1010142 | HIGH | 7.5 | 2.8% | Jul 19, 2019 | scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsi... |
| CVE-2019-1010136 | — | — | 1.7% | Jul 19, 2019 | ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impa... |
| CVE-2019-1010113 | — | — | 0.8% | Jul 19, 2019 | Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might... |
| CVE-2019-1010101 | — | — | 3.4% | Jul 19, 2019 | Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with... |
| CVE-2019-1010100 | — | — | 1.3% | Jul 19, 2019 | Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code executio... |
| CVE-2019-1167 | — | — | 1.1% | Jul 19, 2019 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attac... |
| CVE-2019-13984 | — | — | 1.6% | Jul 19, 2019 | Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a ... |
| CVE-2019-13983 | — | — | 1.5% | Jul 19, 2019 | Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Serv... |
| CVE-2019-13982 | — | — | 1.1% | Jul 19, 2019 | interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a ... |
| CVE-2019-13981 | — | — | 1.5% | Jul 19, 2019 | In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the upl... |
| CVE-2019-13980 | — | — | 2.5% | Jul 19, 2019 | In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to ... |
| CVE-2019-13979 | — | — | 2.6% | Jul 19, 2019 | In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execut... |
| CVE-2019-1010247 | — | — | 1.3% | Jul 19, 2019 | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecti... |
| CVE-2019-1010245 | — | — | 3.6% | Jul 19, 2019 | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact... |
| CVE-2019-12946 | — | — | 1.4% | Jul 19, 2019 | Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now