2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13114 | MEDIUM | 6.5 | 2.1% | Jun 30, 2019 | http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer ... |
| CVE-2019-13113 | MEDIUM | 6.5 | 2.1% | Jun 30, 2019 | Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid dat... |
| CVE-2019-13112 | MEDIUM | 6.5 | 2.0% | Jun 30, 2019 | A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denia... |
| CVE-2019-13111 | MEDIUM | 5.5 | 0.8% | Jun 30, 2019 | A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (larg... |
| CVE-2019-13110 | MEDIUM | 6.5 | 1.9% | Jun 30, 2019 | A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cau... |
| CVE-2019-13109 | MEDIUM | 6.5 | 1.6% | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG ... |
| CVE-2019-13108 | MEDIUM | 6.5 | 1.4% | Jun 30, 2019 | An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG ... |
| CVE-2019-13107 | CRITICAL | 9.8 | 1.8% | Jun 30, 2019 | Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c |
| CVE-2019-13086 | — | — | 32.0% | Jun 30, 2019 | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP U... |
| CVE-2019-13085 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa. |
| CVE-2019-13084 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739. |
| CVE-2019-13083 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a. |
| CVE-2019-13082 | — | — | 4.0% | Jun 30, 2019 | Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It... |
| CVE-2019-11829 | CRITICAL | 9.8 | 2.2% | Jun 30, 2019 | OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote ... |
| CVE-2019-11828 | MEDIUM | 5.4 | 0.7% | Jun 30, 2019 | Cross-site scripting (XSS) vulnerability in Chart in Synology Office before 3.1.4-2771 allows remote authenticated users... |
| CVE-2019-11827 | MEDIUM | 5.4 | 0.8% | Jun 30, 2019 | Cross-site scripting (XSS) vulnerability in SYNO.NoteStation.Shard in Synology Note Station before 2.5.3-0863 allows rem... |
| CVE-2019-11826 | HIGH | 8.8 | 1.7% | Jun 30, 2019 | Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote ... |
| CVE-2019-11825 | MEDIUM | 5.4 | 0.8% | Jun 30, 2019 | Cross-site scripting (XSS) vulnerability in Event Editor in Synology Calendar before 2.3.0-0615 allows remote attackers ... |
| CVE-2019-11822 | MEDIUM | 6.5 | 1.3% | Jun 30, 2019 | Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before ... |
| CVE-2019-11821 | CRITICAL | 9.8 | 1.7% | Jun 30, 2019 | SQL injection vulnerability in synophoto_csPhotoDB.php in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 ... |
| CVE-2019-13075 | — | — | 1.9% | Jun 30, 2019 | Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's ... |
| CVE-2019-13072 | MEDIUM | 5.4 | 0.9% | Jun 30, 2019 | Stored XSS in the Filters page (Name field) in ZoneMinder 1.32.3 allows a malicious user to embed and execute JavaScript... |
| CVE-2019-13068 | — | — | 51.9% | Jun 30, 2019 | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the ... |
| CVE-2019-13067 | — | — | 1.6% | Jun 30, 2019 | njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after t... |
| CVE-2019-13055 | — | — | 1.0% | Jun 29, 2019 | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now