2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12765 | CRITICAL | 9.8 | 10.5% | Jun 11, 2019 | An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable to CSV injection. |
| CVE-2019-10160 | CRITICAL | 9.8 | 5.2% | Jun 7, 2019 | A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 af... |
| CVE-2019-3723 | CRITICAL | 9.1 | 1.8% | Jun 6, 2019 | Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain a web parameter t... |
| CVE-2019-7671 | CRITICAL | 9 | 8.3% | Jun 5, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret... |
| CVE-2019-12739 | CRITICAL | 9 | 2.6% | Jun 5, 2019 | lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution vi... |
| CVE-2019-10149 | CRITICAL | 9.8 | 100.0% | Jun 5, 2019 | A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(... |
| CVE-2019-11356 | CRITICAL | 9.8 | 7.6% | Jun 3, 2019 | The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execut... |
| CVE-2019-6742 | CRITICAL | 9.8 | 5.9% | Jun 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 pr... |
| CVE-2019-6741 | CRITICAL | 9.3 | 3.2% | Jun 3, 2019 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 pr... |
| CVE-2019-11580 | CRITICAL | 9.8 | 95.4% | Jun 3, 2019 | Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac... |
| CVE-2019-9874 | CRITICAL | 9.8 | 83.9% | May 31, 2019 | Deserialization of Untrusted Data in the Sitecore.Security.AntiCSRF (aka anti CSRF) module in Sitecore CMS 7.0 to 7.2 an... |
| CVE-2019-8457 | CRITICAL | 9.8 | 45.4% | May 30, 2019 | SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when hand... |
| CVE-2019-9670 | CRITICAL | 9.8 | 100.0% | May 29, 2019 | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX... |
| CVE-2019-6958 | CRITICAL | 9.1 | 1.5% | May 29, 2019 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI... |
| CVE-2019-6957 | CRITICAL | 9.8 | 2.0% | May 29, 2019 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI... |
| CVE-2019-12450 | CRITICAL | 9.8 | 2.6% | May 29, 2019 | file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while ... |
| CVE-2019-12165 | CRITICAL | 9.8 | 3.4% | May 29, 2019 | MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6.... |
| CVE-2019-12288 | CRITICAL | 9.8 | 1.6% | May 23, 2019 | An issue was discovered in upgrade_htmls.cgi on VStarcam 100T (C7824WIP) KR75.8.53.20 and 200V (C38S) KR203.18.1.20 devi... |
| CVE-2019-7096 | CRITICAL | 9.8 | 6.4% | May 23, 2019 | Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an use after... |
| CVE-2019-7088 | CRITICAL | 9.8 | 6.5% | May 23, 2019 | Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver... |
| CVE-2019-7107 | CRITICAL | 9.8 | 27.8% | May 23, 2019 | Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation coul... |
| CVE-2019-11873 | CRITICAL | 9.8 | 8.8% | May 23, 2019 | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client ... |
| CVE-2019-6808 | CRITICAL | 9.8 | 8.2% | May 22, 2019 | A CWE-284: Improper Access Control vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quant... |
| CVE-2019-6814 | CRITICAL | 9.8 | 36.6% | May 22, 2019 | A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh... |
| CVE-2019-11634 | CRITICAL | 9.8 | 8.0% | May 22, 2019 | Citrix Workspace App before 1904 for Windows has Incorrect Access Control. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now