2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11218 | — | — | 1.2% | Apr 24, 2019 | Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server... |
| CVE-2019-11217 | — | — | 3.8% | Apr 24, 2019 | The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the conte... |
| CVE-2019-10008 | — | — | 19.7% | Apr 24, 2019 | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session... |
| CVE-2019-9951 | — | — | 1.7% | Apr 24, 2019 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M... |
| CVE-2019-9950 | — | — | 2.3% | Apr 24, 2019 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M... |
| CVE-2019-9635 | — | — | 0.5% | Apr 24, 2019 | NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file. |
| CVE-2019-10691 | — | — | 2.8% | Apr 24, 2019 | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting... |
| CVE-2019-3882 | MEDIUM | 5.5 | 0.5% | Apr 24, 2019 | A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory ... |
| CVE-2019-3868 | LOW | 3.8 | 1.0% | Apr 24, 2019 | Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for bro... |
| CVE-2019-3793 | CRITICAL | 9.8 | 1.1% | Apr 24, 2019 | Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x p... |
| CVE-2019-3789 | MEDIUM | 6.5 | 0.8% | Apr 24, 2019 | Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to ro... |
| CVE-2019-3786 | HIGH | 7.1 | 0.6% | Apr 24, 2019 | Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup script... |
| CVE-2019-9928 | — | — | 6.0% | Apr 24, 2019 | GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a ser... |
| CVE-2019-9734 | — | — | 1.6% | Apr 24, 2019 | Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of c... |
| CVE-2019-7214 | — | — | 83.3% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co... |
| CVE-2019-7213 | — | — | 42.1% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary... |
| CVE-2019-7212 | — | — | 1.0% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access othe... |
| CVE-2019-7211 | — | — | 0.7% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by ... |
| CVE-2019-11081 | — | — | 1.8% | Apr 24, 2019 | A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative a... |
| CVE-2019-11032 | MEDIUM | 6.1 | 0.9% | Apr 24, 2019 | In EasyToRecruit (E2R) before 2.11, the upload feature and the Candidate Profile Management feature are prone to Cross S... |
| CVE-2019-10239 | — | — | 0.4% | Apr 24, 2019 | Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un... |
| CVE-2019-9724 | — | — | 1.4% | Apr 24, 2019 | aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File w... |
| CVE-2019-11498 | MEDIUM | 6.5 | 3.0% | Apr 24, 2019 | WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depen... |
| CVE-2019-11490 | — | — | 0.7% | Apr 24, 2019 | An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendq... |
| CVE-2019-11487 | HIGH | 7.8 | 0.7% | Apr 23, 2019 | The Linux kernel before 5.1-rc5 allows page->_refcount reference count overflow, with resultant use-after-free issues, i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now