2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0218 | — | — | 5.1% | Apr 22, 2019 | A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mai... |
| CVE-2019-5428 | — | — | — | Apr 22, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11358. Reason: This candidate is a duplicate of ... |
| CVE-2019-5427 | HIGH | 7.5 | 4.9% | Apr 22, 2019 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protect... |
| CVE-2019-11461 | — | — | 0.3% | Apr 22, 2019 | An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may e... |
| CVE-2019-11384 | — | — | 1.0% | Apr 22, 2019 | The Zalora application 6.15.1 for Android stores confidential information insecurely on the system (i.e. plain text), wh... |
| CVE-2019-10248 | — | — | 0.4% | Apr 22, 2019 | Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. An... |
| CVE-2019-9955 | — | — | 20.9% | Apr 22, 2019 | On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U... |
| CVE-2019-10247 | MEDIUM | 5.3 | 5.8% | Apr 22, 2019 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any O... |
| CVE-2019-10246 | MEDIUM | 5.3 | 4.0% | Apr 22, 2019 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the full... |
| CVE-2019-10241 | MEDIUM | 6.1 | 9.6% | Apr 22, 2019 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS condi... |
| CVE-2019-6157 | MEDIUM | 6.5 | 1.3% | Apr 22, 2019 | In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture... |
| CVE-2019-6155 | MEDIUM | 4.1 | 0.8% | Apr 22, 2019 | A potential vulnerability was found in an SMI handler in various BIOS versions of certain legacy IBM System x and IBM Bl... |
| CVE-2019-3902 | MEDIUM | 5.1 | 1.4% | Apr 22, 2019 | A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path... |
| CVE-2019-3901 | MEDIUM | 4.7 | 0.3% | Apr 22, 2019 | A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant... |
| CVE-2019-3899 | CRITICAL | 9.8 | 1.4% | Apr 22, 2019 | It was found that default configuration of Heketi does not require any authentication potentially exposing the managemen... |
| CVE-2019-11456 | — | — | 0.9% | Apr 22, 2019 | Gila CMS 1.10.1 allows fm/save CSRF for executing arbitrary PHP code. |
| CVE-2019-11455 | HIGH | 8.1 | 3.1% | Apr 22, 2019 | A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker ... |
| CVE-2019-11454 | MEDIUM | 6.1 | 2.4% | Apr 22, 2019 | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash Monit before 5.25.3 allows a remote unauthenticate... |
| CVE-2019-11452 | — | — | 1.3% | Apr 22, 2019 | whatsns 4.0 allows index.php?admin_category/remove.html cid[] SQL injection. |
| CVE-2019-11451 | — | — | 1.3% | Apr 22, 2019 | whatsns 4.0 allows index.php?inform/add.html qid SQL injection. |
| CVE-2019-11450 | — | — | 1.5% | Apr 22, 2019 | whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection. |
| CVE-2019-11244 | MEDIUM | 5 | 0.5% | Apr 22, 2019 | In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $... |
| CVE-2019-11243 | HIGH | 8.1 | 1.5% | Apr 22, 2019 | In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config... |
| CVE-2019-11449 | — | — | 0.9% | Apr 22, 2019 | I, Librarian 4.10 has XSS via the notes.php notes parameter. |
| CVE-2019-11448 | — | — | 12.4% | Apr 22, 2019 | An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now