2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18388 | MEDIUM | 5.5 | 0.3% | Dec 23, 2019 | A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of... |
| CVE-2019-19930 | MEDIUM | 6.5 | 1.1% | Dec 23, 2019 | In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can... |
| CVE-2019-11050 | MEDIUM | 6.5 | 7.4% | Dec 23, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11047 | MEDIUM | 6.5 | 7.3% | Dec 23, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7... |
| CVE-2019-11046 | MEDIUM | 5.3 | 4.1% | Dec 23, 2019 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, includ... |
| CVE-2019-11045 | MEDIUM | 5.9 | 8.8% | Dec 23, 2019 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with emb... |
| CVE-2019-19922 | MEDIUM | 5.5 | 0.9% | Dec 22, 2019 | kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows atta... |
| CVE-2019-15584 | MEDIUM | 6.5 | 1.2% | Dec 20, 2019 | A denial of service exists in gitlab <v12.3.2, <v12.2.6, and <v12.1.10 that would let an attacker bypass input validatio... |
| CVE-2019-4744 | MEDIUM | 6.1 | 0.8% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ar... |
| CVE-2019-4743 | MEDIUM | 4.3 | 0.6% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Atta... |
| CVE-2019-4742 | MEDIUM | 6.1 | 0.9% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 could allow a remote attacker to hijack the clicking action of the victim. By pers... |
| CVE-2019-4736 | MEDIUM | 4.3 | 0.4% | Dec 20, 2019 | IBM Financial Transaction Manager 3.0 is vulnerable to cross-site request forgery which could allow an attacker to execu... |
| CVE-2019-4555 | MEDIUM | 5.4 | 0.8% | Dec 20, 2019 | IBM Cognos Analytics 11.0 and 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbit... |
| CVE-2019-4231 | MEDIUM | 4.3 | 0.7% | Dec 20, 2019 | IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute ... |
| CVE-2019-19916 | MEDIUM | 6.1 | 1.6% | Dec 20, 2019 | In Midori Browser 0.5.11 (on Windows 10), Content Security Policy (CSP) is not applied correctly to all parts of multipa... |
| CVE-2019-19692 | MEDIUM | 6.1 | 0.7% | Dec 20, 2019 | Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that ... |
| CVE-2019-19691 | MEDIUM | 4.9 | 1.2% | Dec 20, 2019 | A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by m... |
| CVE-2019-18263 | MEDIUM | 6.5 | 0.2% | Dec 20, 2019 | An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless... |
| CVE-2019-19908 | MEDIUM | 6.1 | 21.2% | Dec 20, 2019 | phpMyChat-Plus 1.98 is vulnerable to reflected XSS via JavaScript injection into the password reset URL. In the URL, the... |
| CVE-2019-19789 | MEDIUM | 6.5 | 1.2% | Dec 20, 2019 | 3S-Smart CODESYS SP Realtime NT before V2.3.7.28, CODESYS Runtime Toolkit 32 bit full before V2.4.7.54, and CODESYS PLCW... |
| CVE-2019-19342 | MEDIUM | 5.3 | 1.1% | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.4, when /websocket is requested and ... |
| CVE-2019-19341 | MEDIUM | 5.5 | 0.3% | Dec 19, 2019 | A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readab... |
| CVE-2019-11294 | MEDIUM | 4.3 | 0.8% | Dec 19, 2019 | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, i... |
| CVE-2019-19910 | MEDIUM | 6.1 | 0.7% | Dec 19, 2019 | The MinervaNeue Skin in MediaWiki from 2019-11-05 to 2019-12-13 (1.35 and/or 1.34) mishandles certain HTML attributes, a... |
| CVE-2019-18955 | MEDIUM | 6.1 | 0.6% | Dec 19, 2019 | The web console in Lansweeper 7.2.105.2 has XSS via the URL path. Product vulnerability has been fixed and disclosed wit... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now