2019 CVE Vulnerabilities
17,624 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-25046 | MEDIUM | 6.1 | 1.8% | Jun 10, 2021 | The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document. |
| CVE-2019-17567 | MEDIUM | 5.3 | 60.3% | Jun 10, 2021 | Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by ... |
| CVE-2019-25045 | HIGH | 7.8 | 0.5% | Jun 7, 2021 | An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_s... |
| CVE-2019-14584 | HIGH | 7.8 | 0.3% | Jun 3, 2021 | Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege... |
| CVE-2019-12067 | MEDIUM | 6.5 | 0.3% | Jun 2, 2021 | The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when... |
| CVE-2019-4730 | HIGH | 7.1 | 2.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da... |
| CVE-2019-4724 | HIGH | 7.5 | 2.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre... |
| CVE-2019-4723 | HIGH | 7.5 | 2.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain credentials from a user's browser via incorre... |
| CVE-2019-4722 | MEDIUM | 4.3 | 1.4% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information via a stack trace due t... |
| CVE-2019-4653 | MEDIUM | 5.4 | 0.8% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4471 | MEDIUM | 6.5 | 1.0% | Jun 1, 2021 | IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information, caused by the failure ... |
| CVE-2019-25030 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | In Versa Director, Versa Analytics and VOS, Passwords are not hashed using an adaptive cryptographic hash function or ke... |
| CVE-2019-25029 | CRITICAL | 9.8 | 2.7% | May 26, 2021 | In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o... |
| CVE-2019-4588 | HIGH | 7.8 | 0.3% | May 26, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us... |
| CVE-2019-14836 | HIGH | 8.8 | 0.6% | May 26, 2021 | A vulnerability was found that the 3scale dev portal does not employ mechanisms for protection against login CSRF. An at... |
| CVE-2019-12348 | CRITICAL | 9.8 | 1.7% | May 24, 2021 | An issue was discovered in zzcms 2019. SQL Injection exists in user/ztconfig.php via the daohang or img POST parameter. |
| CVE-2019-14827 | MEDIUM | 6.1 | 0.7% | May 17, 2021 | A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive ren... |
| CVE-2019-25044 | HIGH | 7.8 | 0.6% | May 14, 2021 | The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the... |
| CVE-2019-10062 | MEDIUM | 6.1 | 1.4% | May 13, 2021 | The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnera... |
| CVE-2019-19276 | MEDIUM | 5.3 | 1.0% | May 12, 2021 | A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions <... |
| CVE-2019-25043 | MEDIUM | 5.3 | 1.2% | May 6, 2021 | ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a "string index out of range" error a... |
| CVE-2019-25042 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that t... |
| CVE-2019-25041 | HIGH | 7.5 | 2.1% | Apr 27, 2021 | Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that... |
| CVE-2019-25040 | HIGH | 7.5 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that thi... |
| CVE-2019-25039 | CRITICAL | 9.8 | 2.0% | Apr 27, 2021 | Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now