2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9218 | — | — | 1.6% | May 29, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo... |
| CVE-2019-9177 | — | — | — | May 29, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-7549 | — | — | 1.0% | May 29, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.5.10, 11.6.x before 11.6.8, a... |
| CVE-2019-12440 | — | — | 2.1% | May 29, 2019 | The Sitecore Rocks plugin before 2.1.149 for Sitecore allows an unauthenticated threat actor to inject malicious command... |
| CVE-2019-4264 | MEDIUM | 5.9 | 1.0% | May 29, 2019 | IBM QRadar SIEM 7.2.8 WinCollect could allow an attacker to obtain sensitive information by spoofing a trusted entity us... |
| CVE-2019-4256 | HIGH | 7.5 | 1.3% | May 29, 2019 | IBM API Connect 5.0.0.0 through 5.0.8.6 uses weaker than expected cryptographic algorithms that could allow an attacker ... |
| CVE-2019-4184 | MEDIUM | 5.4 | 1.0% | May 29, 2019 | IBM Jazz Reporting Service 6.0 through 6.0.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to... |
| CVE-2019-4139 | MEDIUM | 5.4 | 1.0% | May 29, 2019 | IBM Cognos Analytics 11.0, 11.1.0, and 11.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to ... |
| CVE-2019-4138 | MEDIUM | 5.9 | 2.1% | May 29, 2019 | IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 could allow a remote attacker to obtain sensitive informat... |
| CVE-2019-4137 | MEDIUM | 6.1 | 1.3% | May 29, 2019 | IBM Tivoli Storage Productivity Center 5.2.13 through 5.3.0.1 is vulnerable to cross-site scripting. This vulnerability ... |
| CVE-2019-12439 | HIGH | 7.4 | 0.5% | May 29, 2019 | bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular confi... |
| CVE-2019-5589 | — | — | 2.6% | May 28, 2019 | An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthen... |
| CVE-2019-10967 | HIGH | 8.8 | 3.8% | May 28, 2019 | In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded thir... |
| CVE-2019-10965 | HIGH | 8.8 | 3.7% | May 28, 2019 | In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third... |
| CVE-2019-0221 | — | — | 45.6% | May 28, 2019 | The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided... |
| CVE-2019-7394 | HIGH | 8.8 | 2.9% | May 28, 2019 | A privilege escalation vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.... |
| CVE-2019-7393 | MEDIUM | 4.3 | 2.3% | May 28, 2019 | A UI redress vulnerability in the administrative user interface of CA Technologies CA Strong Authentication 9.0.x, 8.2.x... |
| CVE-2019-5440 | — | — | 1.6% | May 28, 2019 | Use of cryptographically weak PRNG in the password recovery token generation of Revive Adserver < v4.2.1 causes a potent... |
| CVE-2019-5436 | HIGH | 7.8 | 49.7% | May 28, 2019 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 ... |
| CVE-2019-5435 | — | — | 4.9% | May 28, 2019 | An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1. |
| CVE-2019-0188 | HIGH | 7.5 | 8.5% | May 28, 2019 | Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an out... |
| CVE-2019-12396 | — | — | — | May 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-5440. Reason: This candidate is a reservation du... |
| CVE-2019-12395 | MEDIUM | 5.3 | 1.6% | May 28, 2019 | In Webbukkit Dynmap 3.0-beta-3 or below, due to a missing login check in servlet/MapStorageHandler.java, an attacker can... |
| CVE-2019-12321 | — | — | — | May 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12317. Reason: This candidate is a reservation d... |
| CVE-2019-12383 | MEDIUM | 4.3 | 2.2% | May 28, 2019 | Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's U... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now