2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11678 | — | — | 9.5% | May 2, 2019 | The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injec... |
| CVE-2019-11677 | — | — | 9.4% | May 2, 2019 | The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML E... |
| CVE-2019-11676 | — | — | 1.9% | May 2, 2019 | The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS at... |
| CVE-2019-11675 | — | — | 0.2% | May 2, 2019 | The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let... |
| CVE-2019-0227 | HIGH | 7.5 | 86.5% | May 1, 2019 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2... |
| CVE-2019-10952 | CRITICAL | 9.8 | 10.0% | May 1, 2019 | An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code exec... |
| CVE-2019-6562 | MEDIUM | 5.4 | 0.7% | May 1, 2019 | In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input... |
| CVE-2019-10954 | HIGH | 7.5 | 6.1% | May 1, 2019 | An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major n... |
| CVE-2019-11641 | — | — | 1.3% | May 1, 2019 | Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal va... |
| CVE-2019-11640 | — | — | 1.9% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_sim... |
| CVE-2019-11639 | — | — | 1.9% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum ... |
| CVE-2019-11638 | — | — | 1.4% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p ... |
| CVE-2019-11637 | — | — | 1.4% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at r... |
| CVE-2019-3791 | — | — | — | May 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-11636 | — | — | 2.2% | May 1, 2019 | Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from... |
| CVE-2019-4258 | MEDIUM | 5.4 | 1.0% | May 1, 2019 | IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 Standard Edition is vulnerable to cross-site scripting. This vulnerabili... |
| CVE-2019-11633 | — | — | 1.4% | May 1, 2019 | HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylm... |
| CVE-2019-11632 | — | — | 1.2% | May 1, 2019 | In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUn... |
| CVE-2019-11631 | — | — | — | May 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-11628 | HIGH | 8.2 | 1.0% | May 1, 2019 | An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 1... |
| CVE-2019-11627 | CRITICAL | 9.8 | 2.8% | Apr 30, 2019 | gpg-key2ps in signing-party 1.1.x and 2.x before 2.10-1 contains an unsafe shell call enabling shell injection via a Use... |
| CVE-2019-0214 | — | — | 4.9% | Apr 30, 2019 | In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the... |
| CVE-2019-0213 | — | — | 4.9% | Apr 30, 2019 | In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. ... |
| CVE-2019-0194 | — | — | 8.5% | Apr 30, 2019 | Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsup... |
| CVE-2019-3939 | CRITICAL | 9.8 | 2.8% | Apr 30, 2019 | Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now