2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11816 | HIGH | 7.2 | 3.3% | May 20, 2019 | Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authe... |
| CVE-2019-10078 | — | — | 4.9% | May 20, 2019 | A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, whic... |
| CVE-2019-10077 | — | — | 4.7% | May 20, 2019 | A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could ... |
| CVE-2019-10076 | — | — | 4.7% | May 20, 2019 | A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which ... |
| CVE-2019-12241 | — | — | 2.3% | May 20, 2019 | The Carts Guru plugin 1.4.5 for WordPress allows Insecure Deserialization via a cartsguru-source cookie to classes/wc-ca... |
| CVE-2019-12240 | — | — | 2.4% | May 20, 2019 | The Virim plugin 0.4 for WordPress allows Insecure Deserialization via s_values, t_values, or c_values in graph.php. |
| CVE-2019-12239 | HIGH | 7.2 | 0.9% | May 20, 2019 | The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj... |
| CVE-2019-8352 | CRITICAL | 9.8 | 6.3% | May 20, 2019 | By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen... |
| CVE-2019-4293 | MEDIUM | 5.3 | 1.8% | May 20, 2019 | IBM Storwize V7000 Unified (2073) 1.6 configuration may allow an attacker to reveal the server version in default instal... |
| CVE-2019-4058 | MEDIUM | 6.5 | 0.9% | May 20, 2019 | IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into exposing interface elements a... |
| CVE-2019-4011 | MEDIUM | 5.4 | 0.7% | May 20, 2019 | IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2019-12222 | — | — | 1.9% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the func... |
| CVE-2019-12221 | MEDIUM | 6.5 | 2.0% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12220 | — | — | 1.9% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12219 | — | — | 2.0% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12218 | — | — | 2.0% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12217 | — | — | 2.3% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12216 | MEDIUM | 6.5 | 2.2% | May 20, 2019 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image... |
| CVE-2019-12215 | — | — | 1.2% | May 20, 2019 | A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to disc... |
| CVE-2019-12214 | — | — | 1.5% | May 20, 2019 | In FreeImage 3.18.0, an out-of-bounds access occurs because of mishandling of the OpenJPEG j2k_read_ppm_v3 function in j... |
| CVE-2019-12213 | MEDIUM | 6.5 | 2.2% | May 20, 2019 | When FreeImage 3.18.0 reads a special TIFF file, the TIFFReadDirectory function in PluginTIFF.cpp always returns 1, lead... |
| CVE-2019-12212 | — | — | 1.9% | May 20, 2019 | When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due ... |
| CVE-2019-12211 | HIGH | 7.5 | 4.2% | May 20, 2019 | When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy... |
| CVE-2019-12208 | — | — | 1.7% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in njs_function_native_call in njs/njs_function.c. |
| CVE-2019-12207 | — | — | 1.8% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now