2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12507 | — | — | 0.9% | May 31, 2019 | An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path ... |
| CVE-2019-12502 | — | — | 0.8% | May 31, 2019 | There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account ... |
| CVE-2019-12500 | — | — | 0.8% | May 31, 2019 | The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because B... |
| CVE-2019-12499 | — | — | 2.0% | May 31, 2019 | Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit co... |
| CVE-2019-12496 | HIGH | 7.5 | 0.7% | May 31, 2019 | An issue was discovered in Hybrid Group Gobot before 1.13.0. The mqtt subsystem skips verification of root CA certificat... |
| CVE-2019-12495 | — | — | 1.2% | May 31, 2019 | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-by... |
| CVE-2019-12493 | — | — | 1.3% | May 31, 2019 | A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparat... |
| CVE-2019-12483 | HIGH | 7.8 | 1.2% | May 30, 2019 | An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNoti... |
| CVE-2019-12482 | HIGH | 7.5 | 1.7% | May 30, 2019 | An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_t... |
| CVE-2019-12481 | MEDIUM | 5.5 | 0.9% | May 30, 2019 | An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in... |
| CVE-2019-12480 | — | — | 33.7% | May 30, 2019 | BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a... |
| CVE-2019-9723 | — | — | 1.3% | May 30, 2019 | LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and... |
| CVE-2019-8457 | CRITICAL | 9.8 | 45.4% | May 30, 2019 | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when hand... |
| CVE-2019-11091 | MEDIUM | 5.6 | 0.6% | May 30, 2019 | Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing specul... |
| CVE-2019-12461 | — | — | 9.9% | May 30, 2019 | Web Port 1.19.1 allows XSS via the /log type parameter. |
| CVE-2019-12460 | — | — | 3.8% | May 30, 2019 | Web Port 1.19.1 allows XSS via the /access/setup type parameter. |
| CVE-2019-12459 | MEDIUM | 5.3 | 1.8% | May 30, 2019 | FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 201... |
| CVE-2019-12458 | MEDIUM | 5.3 | 1.8% | May 30, 2019 | FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2019-12457 | MEDIUM | 5.3 | 1.8% | May 30, 2019 | FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01. |
| CVE-2019-12456 | — | — | 0.4% | May 30, 2019 | An issue was discovered in the MPT3COMMAND case in _ctl_ioctl_main in drivers/scsi/mpt3sas/mpt3sas_ctl.c in the Linux ke... |
| CVE-2019-12455 | — | — | 0.4% | May 30, 2019 | An issue was discovered in sunxi_divs_clk_setup in drivers/clk/sunxi/clk-sunxi.c in the Linux kernel through 5.1.5. Ther... |
| CVE-2019-12454 | — | — | 0.4% | May 30, 2019 | An issue was discovered in wcd9335_codec_enable_dec in sound/soc/codecs/wcd9335.c in the Linux kernel through 5.1.5. It ... |
| CVE-2019-9670 | CRITICAL | 9.8 | 100.0% | May 29, 2019 | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX... |
| CVE-2019-6981 | — | — | 1.2% | May 29, 2019 | Zimbra Collaboration Suite 8.7.x through 8.8.11 allows Blind SSRF in the Feed component. |
| CVE-2019-6980 | — | — | 3.9% | May 29, 2019 | Synacor Zimbra Collaboration Suite 8.7.x through 8.8.11 allows insecure object deserialization in the IMAP component. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now