2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-20055 | MEDIUM | 6.5 | 0.9% | Dec 29, 2019 | LuquidPixels LiquiFire OS 4.8.0 allows SSRF via the call%3Durl substring followed by a URL in square brackets. |
| CVE-2019-20054 | MEDIUM | 5.5 | 0.5% | Dec 28, 2019 | In the Linux kernel before 5.0.6, there is a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, r... |
| CVE-2019-20053 | MEDIUM | 5.5 | 1.2% | Dec 27, 2019 | An invalid memory address dereference was discovered in the canUnpack function in p_mach.cpp in UPX 3.95 via a crafted M... |
| CVE-2019-20052 | MEDIUM | 6.5 | 1.1% | Dec 27, 2019 | A memory leak was discovered in Mat_VarCalloc in mat.c in matio 1.5.17 because SafeMulDims does not consider the rank==0... |
| CVE-2019-20051 | MEDIUM | 5.5 | 0.9% | Dec 27, 2019 | A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability cause... |
| CVE-2019-20043 | MEDIUM | 4.3 | 2.5% | Dec 27, 2019 | In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users w... |
| CVE-2019-20042 | MEDIUM | 6.1 | 2.8% | Dec 27, 2019 | In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular... |
| CVE-2019-20024 | MEDIUM | 6.5 | 1.0% | Dec 27, 2019 | A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4. |
| CVE-2019-20023 | MEDIUM | 6.5 | 1.0% | Dec 27, 2019 | A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4. |
| CVE-2019-20022 | MEDIUM | 6.5 | 0.9% | Dec 27, 2019 | An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3. |
| CVE-2019-20021 | MEDIUM | 5.5 | 1.1% | Dec 27, 2019 | A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file. |
| CVE-2019-20020 | MEDIUM | 6.5 | 0.9% | Dec 27, 2019 | A stack-based buffer over-read was discovered in ReadNextStructField in mat5.c in matio 1.5.17. |
| CVE-2019-20019 | MEDIUM | 6.5 | 0.9% | Dec 27, 2019 | An attempted excessive memory allocation was discovered in Mat_VarRead5 in mat5.c in matio 1.5.17. |
| CVE-2019-20018 | MEDIUM | 6.5 | 1.1% | Dec 27, 2019 | A stack-based buffer over-read was discovered in ReadNextCell in mat5.c in matio 1.5.17. |
| CVE-2019-20017 | MEDIUM | 6.5 | 0.9% | Dec 27, 2019 | A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17. |
| CVE-2019-20016 | MEDIUM | 6.5 | 1.7% | Dec 27, 2019 | libmysofa before 2019-11-24 does not properly restrict recursive function calls, as demonstrated by reports of stack con... |
| CVE-2019-20015 | MEDIUM | 6.5 | 1.4% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg... |
| CVE-2019-20013 | MEDIUM | 6.5 | 1.4% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation... |
| CVE-2019-20012 | MEDIUM | 6.5 | 1.4% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg... |
| CVE-2019-20009 | MEDIUM | 6.5 | 1.4% | Dec 27, 2019 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation... |
| CVE-2019-20008 | MEDIUM | 5.4 | 0.8% | Dec 26, 2019 | In Archery before 1.3, inserting an XSS payload into a project name (either by creating a new project or editing an exis... |
| CVE-2019-20007 | MEDIUM | 6.5 | 1.3% | Dec 26, 2019 | An issue was discovered in ezXML 0.8.2 through 0.8.6. The function ezxml_str2utf8, while parsing a crafted XML file, per... |
| CVE-2019-20005 | MEDIUM | 6.5 | 1.2% | Dec 26, 2019 | An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo... |
| CVE-2019-19389 | MEDIUM | 5.4 | 0.8% | Dec 26, 2019 | JetBrains Ktor framework before version 1.2.6 was vulnerable to HTTP Response Splitting. |
| CVE-2019-5272 | MEDIUM | 4.9 | 0.3% | Dec 26, 2019 | USG9500 with versions of V500R001C30;V500R001C60 have a missing integrity checking vulnerability. The software of the af... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now