2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1010039 | — | — | 2.3% | Jul 15, 2019 | uLaunchELF < commit 170827a is affected by: Buffer Overflow. The impact is: Possible code execution and denial of servic... |
| CVE-2019-1010038 | — | — | 2.5% | Jul 15, 2019 | OpenModelica OMCompiler is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. T... |
| CVE-2019-1010034 | — | — | 1.4% | Jul 15, 2019 | Deepwoods Software WebLibrarian 3.5.2 and earlier is affected by: SQL Injection. The impact is: Exposing the entire data... |
| CVE-2019-1010030 | — | — | — | Jul 15, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11501. Reason: This candidate is a reservation d... |
| CVE-2019-1010028 | — | — | 0.7% | Jul 15, 2019 | phpscriptsmall.com School College Portal with ERP Script 2.6.1 and earlier is affected by: Cross Site Scripting (XSS). T... |
| CVE-2019-1010025 | — | — | 2.3% | Jul 15, 2019 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_crea... |
| CVE-2019-1010024 | — | — | 3.2% | Jul 15, 2019 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack ... |
| CVE-2019-1010023 | MEDIUM | 5.4 | 3.1% | Jul 15, 2019 | GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case... |
| CVE-2019-1010022 | — | — | 3.2% | Jul 15, 2019 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The compo... |
| CVE-2019-1010017 | — | — | 1.6% | Jul 15, 2019 | libnmap < v0.6.3 is affected by: XML Injection. The impact is: Denial of service (DoS) by consuming resources. The compo... |
| CVE-2019-1010016 | — | — | 1.0% | Jul 15, 2019 | Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/prod... |
| CVE-2019-1010011 | — | — | — | Jul 15, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10753, CVE-2018-10771. Reason: This candidate is... |
| CVE-2019-1010009 | — | — | 2.8% | Jul 15, 2019 | DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential ... |
| CVE-2019-1010008 | — | — | 0.9% | Jul 15, 2019 | OpenEnergyMonitor Project Emoncms 9.8.8 is affected by: Cross Site Scripting (XSS). The impact is: Theoretically low, bu... |
| CVE-2019-1010006 | HIGH | 7.8 | 2.1% | Jul 15, 2019 | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/ti... |
| CVE-2019-1010005 | — | — | 1.2% | Jul 15, 2019 | HexoEditor v1.1.8-beta is affected by: XSS to code execution. |
| CVE-2019-1010004 | — | — | 1.3% | Jul 15, 2019 | SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The compon... |
| CVE-2019-13602 | HIGH | 7.8 | 2.1% | Jul 14, 2019 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 all... |
| CVE-2019-13598 | — | — | 4.2% | Jul 14, 2019 | LuaUPnP in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via t... |
| CVE-2019-13597 | — | — | 14.3% | Jul 14, 2019 | _s_/sprm/_s_/dyn/Player_setScriptFile in Sahi Pro 8.0.0 allows command execution. It allows one to run ".sah" scripts vi... |
| CVE-2019-13594 | — | — | 0.6% | Jul 14, 2019 | In Mirumee Saleor 2.7.0 (fixed in 2.8.0), CSRF protection middleware was accidentally disabled, which allowed attackers ... |
| CVE-2019-13590 | MEDIUM | 5.5 | 1.1% | Jul 14, 2019 | An issue was discovered in libsox.a in SoX 14.4.2. In sox-fmt.h (startread function), there is an integer overflow on th... |
| CVE-2019-13589 | — | — | 4.3% | Jul 14, 2019 | The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third... |
| CVE-2019-5629 | HIGH | 7.8 | 0.9% | Jul 13, 2019 | Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL sear... |
| CVE-2019-13161 | MEDIUM | 5.3 | 4.0% | Jul 12, 2019 | An issue was discovered in Asterisk Open Source through 13.27.0, 14.x and 15.x through 15.7.2, and 16.x through 16.4.0, ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now