2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11035 | CRITICAL | 9.1 | 4.3% | Apr 18, 2019 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3... |
| CVE-2019-11034 | CRITICAL | 9.1 | 4.0% | Apr 18, 2019 | When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.28, 7.2.x below 7.2.17 and 7.3.x below 7.3... |
| CVE-2019-10306 | CRITICAL | 9.9 | 2.4% | Apr 18, 2019 | A sandbox bypass vulnerability in Jenkins ontrack Plugin 3.4 and earlier allowed attackers with control over ontrack DSL... |
| CVE-2019-1710 | CRITICAL | 9.8 | 2.8% | Apr 17, 2019 | A vulnerability in the sysadmin virtual machine (VM) on Cisco ASR 9000 Series Aggregation Services Routers running Cisco... |
| CVE-2019-0228 | CRITICAL | 9.8 | 9.5% | Apr 17, 2019 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XM... |
| CVE-2019-6579 | CRITICAL | 9.8 | 2.3% | Apr 17, 2019 | A vulnerability has been identified in Spectrum Power 4 (with Web Office Portal). An attacker with network access to the... |
| CVE-2019-4203 | CRITICAL | 9.8 | 1.7% | Apr 15, 2019 | IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from... |
| CVE-2019-4202 | CRITICAL | 10 | 4.2% | Apr 15, 2019 | IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially cr... |
| CVE-2019-4012 | CRITICAL | 9.8 | 2.1% | Apr 15, 2019 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker cou... |
| CVE-2019-6526 | CRITICAL | 9.8 | 1.0% | Apr 15, 2019 | Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and pr... |
| CVE-2019-10880 | CRITICAL | 9.8 | 8.5% | Apr 12, 2019 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user... |
| CVE-2019-11068 | CRITICAL | 9.8 | 5.2% | Apr 10, 2019 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permi... |
| CVE-2019-0040 | CRITICAL | 9.1 | 1.9% | Apr 10, 2019 | On Junos OS, rpcbind should only be listening to port 111 on the internal routing instance (IRI). External packets desti... |
| CVE-2019-0036 | CRITICAL | 9.8 | 1.0% | Apr 10, 2019 | When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", ... |
| CVE-2019-0008 | CRITICAL | 9.8 | 4.5% | Apr 10, 2019 | A certain sequence of valid BGP or IPv6 BFD packets may trigger a stack based buffer overflow in the Junos OS Packet For... |
| CVE-2019-7551 | CRITICAL | 9 | 1.8% | Apr 10, 2019 | Cantemo Portal before 3.2.13, 3.3.x before 3.3.8, and 3.4.x before 3.4.9 has XSS. Leveraging this vulnerability would en... |
| CVE-2019-4013 | CRITICAL | 9 | 14.1% | Apr 10, 2019 | IBM BigFix Platform 9.5 could allow any authenticated user to upload any file to any location on the server with root pr... |
| CVE-2019-6140 | CRITICAL | 9.8 | 1.4% | Apr 9, 2019 | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnera... |
| CVE-2019-9134 | CRITICAL | 9.8 | 1.7% | Apr 9, 2019 | Architectural Information System 1.0 and earlier versions have a Stack-based buffer overflow, allows remote attackers to... |
| CVE-2019-6552 | CRITICAL | 9.8 | 3.3% | Apr 5, 2019 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of pro... |
| CVE-2019-6550 | CRITICAL | 9.8 | 6.1% | Apr 5, 2019 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a l... |
| CVE-2019-6553 | CRITICAL | 9.8 | 50.0% | Apr 4, 2019 | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in... |
| CVE-2019-7001 | CRITICAL | 9.9 | 1.2% | Apr 4, 2019 | A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker t... |
| CVE-2019-5421 | CRITICAL | 9.8 | 1.6% | Apr 3, 2019 | Plataformatec Devise version 4.5.0 and earlier, using the lockable module contains a CWE-367 vulnerability in The `Devis... |
| CVE-2019-7475 | CRITICAL | 9.8 | 1.4% | Apr 2, 2019 | A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now