2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9842 | — | — | 2.2% | Jun 14, 2019 | madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element wit... |
| CVE-2019-12828 | — | — | 13.3% | Jun 14, 2019 | An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and orig... |
| CVE-2019-0316 | — | — | 0.6% | Jun 14, 2019 | SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not... |
| CVE-2019-0303 | — | — | 0.8% | Jun 14, 2019 | SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appServic... |
| CVE-2019-2259 | — | — | 0.9% | Jun 14, 2019 | Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto,... |
| CVE-2019-2257 | — | — | 0.2% | Jun 14, 2019 | Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity,... |
| CVE-2019-2256 | — | — | 1.5% | Jun 14, 2019 | An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr... |
| CVE-2019-2255 | — | — | 1.5% | Jun 14, 2019 | An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr... |
| CVE-2019-4403 | MEDIUM | 5.4 | 0.7% | Jun 14, 2019 | IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2019-4381 | MEDIUM | 5.5 | 0.4% | Jun 14, 2019 | IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node... |
| CVE-2019-4239 | MEDIUM | 5.5 | 0.3% | Jun 14, 2019 | IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which c... |
| CVE-2019-12822 | — | — | 8.8% | Jun 14, 2019 | In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory asserti... |
| CVE-2019-11770 | HIGH | 8.1 | 1.3% | Jun 14, 2019 | In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over ... |
| CVE-2019-11582 | — | — | 4.9% | Jun 14, 2019 | An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, ... |
| CVE-2019-10159 | MEDIUM | 4.3 | 0.7% | Jun 14, 2019 | cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorizati... |
| CVE-2019-10126 | CRITICAL | 9.8 | 6.8% | Jun 14, 2019 | A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net... |
| CVE-2019-12819 | — | — | 0.6% | Jun 14, 2019 | An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c ... |
| CVE-2019-12818 | — | — | 5.5% | Jun 14, 2019 | An issue was discovered in the Linux kernel before 4.20.15. The nfc_llcp_build_tlv function in net/nfc/llcp_commands.c m... |
| CVE-2019-12813 | — | — | 1.1% | Jun 13, 2019 | An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating th... |
| CVE-2019-12802 | HIGH | 7.8 | 1.6% | Jun 13, 2019 | In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remot... |
| CVE-2019-10962 | MEDIUM | 5.3 | 1.7% | Jun 13, 2019 | BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on ... |
| CVE-2019-10959 | — | — | 2.5% | Jun 13, 2019 | BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13,... |
| CVE-2019-12799 | HIGH | 8.8 | 54.7% | Jun 13, 2019 | In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat... |
| CVE-2019-7321 | — | — | 3.2% | Jun 13, 2019 | Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vuln... |
| CVE-2019-12798 | — | — | 1.7% | Jun 13, 2019 | An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, l... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now