2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1010174 | CRITICAL | 9.8 | 4.9% | Jul 25, 2019 | CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_... |
| CVE-2019-1010178 | CRITICAL | 9.8 | 4.6% | Jul 24, 2019 | Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execut... |
| CVE-2019-11710 | CRITICAL | 9.8 | 1.7% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed ev... |
| CVE-2019-11709 | CRITICAL | 9.8 | 2.3% | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of... |
| CVE-2019-11708 | CRITICAL | 10 | 55.9% | Jul 23, 2019 | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result... |
| CVE-2019-11705 | CRITICAL | 9.8 | 9.9% | Jul 23, 2019 | A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processin... |
| CVE-2019-11704 | CRITICAL | 9.8 | 10.5% | Jul 23, 2019 | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when proce... |
| CVE-2019-11703 | CRITICAL | 9.8 | 10.5% | Jul 23, 2019 | A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing cer... |
| CVE-2019-1010155 | CRITICAL | 9.1 | 8.6% | Jul 23, 2019 | D-Link DSL-2750U 1.11 is affected by: Authentication Bypass. The impact is: denial of service and information leakage. T... |
| CVE-2019-10173 | CRITICAL | 9.8 | 94.8% | Jul 23, 2019 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. ... |
| CVE-2019-12328 | CRITICAL | 9 | 4.2% | Jul 22, 2019 | A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of t... |
| CVE-2019-1010228 | CRITICAL | 9.8 | 7.6% | Jul 22, 2019 | OFFIS.de DCMTK 3.6.3 and below is affected by: Buffer Overflow. The impact is: Possible code execution and confirmed Den... |
| CVE-2019-12815 | CRITICAL | 9.8 | 57.6% | Jul 19, 2019 | An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and informatio... |
| CVE-2019-1010238 | CRITICAL | 9.8 | 6.3% | Jul 19, 2019 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to... |
| CVE-2019-13962 | CRITICAL | 9.8 | 3.6% | Jul 18, 2019 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer ove... |
| CVE-2019-13952 | CRITICAL | 9.8 | 1.6% | Jul 18, 2019 | The set_ipv6() function in zscan_rfc1035.rl in gdnsd before 2.4.3 and 3.x before 3.2.1 has a stack-based buffer overflow... |
| CVE-2019-3570 | CRITICAL | 9.8 | 1.7% | Jul 18, 2019 | Call to the scrypt_enc() function in HHVM can lead to heap corruption by using specifically crafted parameters (N, r and... |
| CVE-2019-13575 | CRITICAL | 9.8 | 2.6% | Jul 18, 2019 | A SQL injection vulnerability exists in WPEverest Everest Forms plugin for WordPress through 1.4.9. Successful exploitat... |
| CVE-2019-1917 | CRITICAL | 9.1 | 5.3% | Jul 17, 2019 | A vulnerability in the REST API interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remot... |
| CVE-2019-13585 | CRITICAL | 9.8 | 15.2% | Jul 17, 2019 | The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 has a Buffer Overflow via a forged HTTP reque... |
| CVE-2019-13573 | CRITICAL | 9.8 | 4.4% | Jul 17, 2019 | A SQL injection vulnerability exists in the FolioVision FV Flowplayer Video Player plugin before 7.3.19.727 for WordPres... |
| CVE-2019-9848 | CRITICAL | 9.8 | 30.7% | Jul 17, 2019 | LibreOffice has a feature where documents can specify that pre-installed scripts can be executed on various document eve... |
| CVE-2019-12989 | CRITICAL | 9.8 | 94.4% | Jul 16, 2019 | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection. |
| CVE-2019-6824 | CRITICAL | 9.8 | 4.5% | Jul 15, 2019 | A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthen... |
| CVE-2019-6823 | CRITICAL | 9.8 | 5.0% | Jul 15, 2019 | A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an una... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now