2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12206 | — | — | 2.0% | May 20, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in nxt_utf8_encode in nxt_utf8.c. |
| CVE-2019-11809 | — | — | 0.8% | May 20, 2019 | An issue was discovered in Joomla! before 3.9.6. The debug views of com_users do not properly escape user supplied data,... |
| CVE-2019-12198 | — | — | 1.3% | May 20, 2019 | In GoHttp through 2017-07-25, there is a stack-based buffer over-read via a long User-Agent header. |
| CVE-2019-12185 | — | — | 18.1% | May 20, 2019 | eLabFTW 1.8.5 is vulnerable to arbitrary file uploads via the /app/controllers/EntityController.php component. This may ... |
| CVE-2019-12184 | — | — | 0.7% | May 19, 2019 | There is XSS in browser/components/MarkdownPreview.js in BoostIO Boostnote 0.11.15 via a label named flowchart, sequence... |
| CVE-2019-12173 | — | — | 3.8% | May 18, 2019 | MacDown 0.7.1 (870) allows remote code execution via a file:\\\ URI, with a .app pathname, in the HREF attribute of an A... |
| CVE-2019-12172 | — | — | 1.8% | May 17, 2019 | Typora 0.9.9.21.1 (1913) allows arbitrary code execution via a modified file: URL syntax in the HREF attribute of an ARE... |
| CVE-2019-12170 | — | — | 8.7% | May 17, 2019 | ATutor through 2.2.4 is vulnerable to arbitrary file uploads via the mods/_core/backups/upload.php (aka backup) componen... |
| CVE-2019-12168 | — | — | 5.0% | May 17, 2019 | Four-Faith Wireless Mobile Router F3x24 v1.0 devices allow remote code execution via the Command Shell (aka Administrati... |
| CVE-2019-12163 | MEDIUM | 5.3 | 2.8% | May 17, 2019 | GAT-Ship Web Module through 1.30 allows remote attackers to obtain potentially sensitive information via {} in a ws/gats... |
| CVE-2019-11644 | — | — | 1.3% | May 17, 2019 | In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Ant... |
| CVE-2019-8339 | — | — | 0.5% | May 17, 2019 | An issue was discovered in Falco through 0.14.0. A missing indicator for insufficient resources allows local users to by... |
| CVE-2019-12161 | — | — | 1.1% | May 17, 2019 | WPO WebPageTest 19.04 allows SSRF because ValidateURL in www/runtest.php does not consider octal encoding of IP addresse... |
| CVE-2019-12160 | — | — | 1.7% | May 17, 2019 | GoHTTP through 2017-07-25 has a sendHeader use-after-free. |
| CVE-2019-12159 | — | — | 1.3% | May 17, 2019 | GoHTTP through 2017-07-25 has a stack-based buffer over-read in the scan function (when called from getRequestType) via ... |
| CVE-2019-12158 | — | — | 1.6% | May 17, 2019 | GoHTTP through 2017-07-25 has a GetExtension heap-based buffer overflow via a long extension. |
| CVE-2019-7353 | — | — | 1.5% | May 17, 2019 | An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition 11.7.x before 11.7.4. GitLab... |
| CVE-2019-12086 | HIGH | 7.5 | 21.9% | May 17, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled... |
| CVE-2019-11887 | — | — | 2.3% | May 17, 2019 | SimplyBook.me through 2019-05-11 does not properly restrict File Upload which could allow remote code execution. |
| CVE-2019-11057 | HIGH | 8.8 | 1.2% | May 17, 2019 | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL comma... |
| CVE-2019-6797 | — | — | 1.5% | May 17, 2019 | An information disclosure issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.... |
| CVE-2019-6790 | — | — | 0.8% | May 17, 2019 | An Incorrect Access Control (issue 2 of 3) issue was discovered in GitLab Community and Enterprise Edition 8.14 and late... |
| CVE-2019-6787 | — | — | 1.2% | May 17, 2019 | An Incorrect Access Control issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before... |
| CVE-2019-6781 | HIGH | 7.5 | 1.2% | May 17, 2019 | An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x befor... |
| CVE-2019-5958 | — | — | 0.9% | May 17, 2019 | Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now