2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7690 | — | — | 3.2% | May 13, 2019 | In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from proce... |
| CVE-2019-4259 | MEDIUM | 5.5 | 0.4% | May 13, 2019 | A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES... |
| CVE-2019-3684 | MEDIUM | 5.9 | 0.7% | May 13, 2019 | SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable ... |
| CVE-2019-12047 | — | — | 1.2% | May 13, 2019 | Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution... |
| CVE-2019-11429 | — | — | 5.9% | May 13, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)... |
| CVE-2019-8350 | MEDIUM | 6.6 | 0.3% | May 13, 2019 | The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an informati... |
| CVE-2019-7411 | — | — | 0.9% | May 13, 2019 | Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authentic... |
| CVE-2019-7409 | — | — | 1.1% | May 13, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbi... |
| CVE-2019-7404 | — | — | 1.5% | May 13, 2019 | An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file v... |
| CVE-2019-12043 | — | — | 0.9% | May 13, 2019 | In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintabl... |
| CVE-2019-12041 | HIGH | 7.5 | 1.3% | May 13, 2019 | lib/common/html_re.js in remarkable 1.7.1 allows Regular Expression Denial of Service (ReDoS) via a CDATA section. |
| CVE-2019-11888 | — | — | 2.7% | May 13, 2019 | Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi... |
| CVE-2019-11886 | — | — | 1.9% | May 13, 2019 | The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all... |
| CVE-2019-11885 | — | — | 0.4% | May 12, 2019 | eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr... |
| CVE-2019-5438 | MEDIUM | 5.3 | 1.5% | May 10, 2019 | Path traversal using symlink in npm harp module versions <= 0.29.0. |
| CVE-2019-5437 | — | — | 1.3% | May 10, 2019 | Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i... |
| CVE-2019-11884 | LOW | 3.3 | 0.5% | May 10, 2019 | The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to ob... |
| CVE-2019-5677 | — | — | 0.3% | May 10, 2019 | NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ... |
| CVE-2019-5676 | MEDIUM | 6.7 | 0.5% | May 10, 2019 | NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly l... |
| CVE-2019-5675 | — | — | 0.4% | May 10, 2019 | NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ... |
| CVE-2019-3566 | MEDIUM | 5.9 | 0.9% | May 10, 2019 | A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a... |
| CVE-2019-5496 | — | — | 0.7% | May 10, 2019 | Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an ... |
| CVE-2019-5495 | — | — | 1.4% | May 10, 2019 | OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security heade... |
| CVE-2019-11066 | — | — | 1.5% | May 10, 2019 | openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method... |
| CVE-2019-11059 | — | — | 1.9% | May 10, 2019 | Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now