2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5433 | — | — | 1.7% | May 6, 2019 | A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted ad... |
| CVE-2019-5432 | HIGH | 7.5 | 1.6% | May 6, 2019 | A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0... |
| CVE-2019-5431 | MEDIUM | 5.4 | 0.4% | May 6, 2019 | This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulner... |
| CVE-2019-5430 | — | — | 0.7% | May 6, 2019 | In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes... |
| CVE-2019-3799 | MEDIUM | 6.5 | 85.3% | May 6, 2019 | Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, an... |
| CVE-2019-3797 | LOW | 3.5 | 1.1% | May 6, 2019 | This affects Spring Data JPA in versions up to and including 2.1.5, 2.0.13 and 1.11.19. Derived queries using any of the... |
| CVE-2019-3565 | HIGH | 7.5 | 2.8% | May 6, 2019 | Legacy C++ Facebook Thrift servers (using cpp instead of cpp2) would not error upon receiving messages with containers o... |
| CVE-2019-3564 | HIGH | 7.5 | 2.0% | May 6, 2019 | Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a resul... |
| CVE-2019-3559 | HIGH | 7.5 | 2.0% | May 6, 2019 | Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a res... |
| CVE-2019-3558 | HIGH | 7.5 | 2.0% | May 6, 2019 | Python Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a r... |
| CVE-2019-3552 | HIGH | 7.5 | 2.0% | May 6, 2019 | C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers of fields of unknown ty... |
| CVE-2019-10249 | HIGH | 8.1 | 0.6% | May 6, 2019 | All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artif... |
| CVE-2019-11767 | — | — | 1.2% | May 5, 2019 | Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the ... |
| CVE-2019-11766 | CRITICAL | 9.8 | 2.1% | May 5, 2019 | dhcp6.c in dhcpcd before 6.11.7 and 7.x before 7.2.2 has a buffer over-read in the D6_OPTION_PD_EXCLUDE feature. |
| CVE-2019-6619 | HIGH | 7.5 | 1.8% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, the Traffic Management Microkernel (TMM) may restart when... |
| CVE-2019-6618 | — | — | 0.9% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource A... |
| CVE-2019-6617 | MEDIUM | 6.5 | 2.3% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource ... |
| CVE-2019-6616 | HIGH | 7.2 | 1.6% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, administrative users with... |
| CVE-2019-6615 | MEDIUM | 4.9 | 1.1% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, Administrator and Resourc... |
| CVE-2019-6614 | MEDIUM | 6.5 | 1.4% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, and 12.1.0-12.1.4, internal methods used to prevent arbitrary file overwrite... |
| CVE-2019-6158 | HIGH | 8.7 | 1.5% | May 3, 2019 | An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being writt... |
| CVE-2019-3894 | HIGH | 8.8 | 1.5% | May 3, 2019 | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a Securi... |
| CVE-2019-3805 | MEDIUM | 4.7 | 0.2% | May 3, 2019 | A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d... |
| CVE-2019-3400 | MEDIUM | 6.1 | 1.1% | May 3, 2019 | The labels gadget in Jira before version 7.13.2, and from version 8.0.0 before version 8.0.2 allows remote attackers to ... |
| CVE-2019-11037 | MEDIUM | 4.9 | 2.0% | May 3, 2019 | In PHP imagick extension in versions between 3.3.0 and 3.4.4, writing to an array of values in ImagickKernel::fromMatrix... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now