2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11839 | — | — | 1.6% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to nj... |
| CVE-2019-11838 | — | — | 1.6% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to ... |
| CVE-2019-11837 | — | — | 1.4% | May 9, 2019 | njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related t... |
| CVE-2019-11353 | — | — | 3.1% | May 9, 2019 | The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in p... |
| CVE-2019-11323 | MEDIUM | 5.9 | 1.3% | May 9, 2019 | HAProxy before 1.9.7 mishandles a reload with rotated keys, which triggers use of uninitialized, and very predictable, H... |
| CVE-2019-0226 | — | — | 1.8% | May 9, 2019 | Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directo... |
| CVE-2019-11836 | — | — | 0.3% | May 9, 2019 | The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persi... |
| CVE-2019-11820 | MEDIUM | 5.5 | 0.3% | May 9, 2019 | Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users... |
| CVE-2019-11835 | CRITICAL | 9.8 | 2.6% | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. |
| CVE-2019-11834 | CRITICAL | 9.8 | 2.5% | May 9, 2019 | cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. |
| CVE-2019-11832 | — | — | 3.9% | May 9, 2019 | TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the app... |
| CVE-2019-11831 | CRITICAL | 9.8 | 5.6% | May 9, 2019 | The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent... |
| CVE-2019-11830 | — | — | 2.7% | May 9, 2019 | PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1... |
| CVE-2019-7442 | — | — | 40.0% | May 8, 2019 | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault... |
| CVE-2019-9698 | — | — | 0.3% | May 8, 2019 | Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulne... |
| CVE-2019-8285 | — | — | 4.4% | May 8, 2019 | Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentiall... |
| CVE-2019-11494 | HIGH | 7.5 | 2.4% | May 8, 2019 | In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects pr... |
| CVE-2019-11458 | — | — | 2.1% | May 8, 2019 | An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can ... |
| CVE-2019-11406 | — | — | 0.9% | May 8, 2019 | Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter. |
| CVE-2019-11398 | — | — | 3.5% | May 8, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra... |
| CVE-2019-5021 | CRITICAL | 9.8 | 6.3% | May 8, 2019 | Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the `root` user. This vulne... |
| CVE-2019-5014 | MEDIUM | 6.5 | 0.6% | May 8, 2019 | An exploitable improper access control vulnerability exists in the bluetooth low energy functionality of Winco Fireworks... |
| CVE-2019-2054 | HIGH | 7.8 | 0.6% | May 8, 2019 | In the seccomp implementation prior to kernel version 4.8, there is a possible seccomp bypass due to seccomp policies th... |
| CVE-2019-2053 | — | — | 0.2% | May 8, 2019 | In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This... |
| CVE-2019-2052 | — | — | 1.0% | May 8, 2019 | In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote inf... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now