2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11390 | MEDIUM | 5.3 | 1.7% | Apr 21, 2019 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PH... |
| CVE-2019-11389 | MEDIUM | 5.3 | 1.7% | Apr 21, 2019 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-933-APPLICATION-ATTACK-PH... |
| CVE-2019-11388 | MEDIUM | 5.3 | 1.6% | Apr 21, 2019 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-932-APPLICATION-ATTACK-RC... |
| CVE-2019-11387 | MEDIUM | 5.3 | 2.4% | Apr 21, 2019 | An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) through 3.1.0. /rules/REQUEST-942-APPLICATION-ATTACK-SQ... |
| CVE-2019-11371 | — | — | 1.6% | Apr 20, 2019 | BWA (aka Burrow-Wheeler Aligner) 0.7.17 r1198 has a Buffer Overflow via a long prefix that is mishandled in bns_fasta2bn... |
| CVE-2019-11378 | — | — | 3.6% | Apr 20, 2019 | An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. I... |
| CVE-2019-11377 | — | — | 1.8% | Apr 20, 2019 | wcms/wex/finder/action.php in WCMS v0.3.2 has a Arbitrary File Upload Vulnerability via developer/finder because .php is... |
| CVE-2019-11376 | — | — | 2.2% | Apr 20, 2019 | SOY CMS v3.0.2 allows remote attackers to execute arbitrary PHP code via a <?php substring in the second text box. NOTE:... |
| CVE-2019-11375 | — | — | 2.6% | Apr 20, 2019 | Msvod v10 has a CSRF vulnerability to change user information via the admin/member/edit.html URI. |
| CVE-2019-11374 | — | — | 9.9% | Apr 20, 2019 | 74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI. |
| CVE-2019-11373 | — | — | 2.5% | Apr 20, 2019 | An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 ... |
| CVE-2019-11372 | — | — | 2.5% | Apr 20, 2019 | An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaAre... |
| CVE-2019-11366 | — | — | 2.1% | Apr 20, 2019 | An issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the curr... |
| CVE-2019-11365 | — | — | 4.3% | Apr 20, 2019 | An issue was discovered in atftpd in atftp 0.7.1. A remote attacker may send a crafted packet triggering a stack-based b... |
| CVE-2019-11362 | — | — | 1.6% | Apr 20, 2019 | app/controllers/frontend/PostController.php in ROCBOSS V2.2.1 has SQL injection via the Post:doReward score paramter, as... |
| CVE-2019-11359 | — | — | 1.1% | Apr 20, 2019 | Cross-site scripting (XSS) vulnerability in display.php in I, Librarian 4.10 allows remote attackers to inject arbitrary... |
| CVE-2019-11358 | MEDIUM | 6.1 | 87.2% | Apr 20, 2019 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus... |
| CVE-2019-11354 | HIGH | 7.8 | 23.1% | Apr 19, 2019 | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori... |
| CVE-2019-11351 | — | — | 3.9% | Apr 19, 2019 | TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework. |
| CVE-2019-11350 | — | — | 1.8% | Apr 19, 2019 | CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage a... |
| CVE-2019-2041 | — | — | 0.2% | Apr 19, 2019 | In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices du... |
| CVE-2019-2040 | — | — | 0.2% | Apr 19, 2019 | In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This c... |
| CVE-2019-2039 | — | — | 0.2% | Apr 19, 2019 | In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could l... |
| CVE-2019-2038 | — | — | 0.4% | Apr 19, 2019 | In rw_i93_process_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could... |
| CVE-2019-2037 | — | — | 0.8% | Apr 19, 2019 | In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out-of-bound read due to an incorrect bounds check. Th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now