2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7155 | — | — | 1.0% | Apr 16, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6... |
| CVE-2019-9845 | — | — | 2.5% | Apr 16, 2019 | madskristensen Miniblog.Core through 2019-01-16 allows remote attackers to execute arbitrary ASPX code via an IMG elemen... |
| CVE-2019-5520 | — | — | 1.0% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-5517 | — | — | 1.1% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-5516 | — | — | 1.7% | Apr 15, 2019 | VMware ESXi (6.7 before ESXi670-201904101-SG and 6.5 before ESXi650-201903001), Workstation (15.x before 15.0.3 and 14.x... |
| CVE-2019-6609 | — | — | 1.5% | Apr 15, 2019 | Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, An... |
| CVE-2019-4203 | CRITICAL | 9.8 | 1.7% | Apr 15, 2019 | IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal can be exploited by app developers to download arbitrary files from... |
| CVE-2019-4202 | CRITICAL | 10 | 4.2% | Apr 15, 2019 | IBM API Connect 5.0.0.0 and 5.0.8.6 Developer Portal is vulnerable to command injection. An attacker with a specially cr... |
| CVE-2019-4178 | MEDIUM | 6.4 | 3.1% | Apr 15, 2019 | IBM Cognos Analytics 11 could allow a remote attacker to traverse directories on the system. An attacker could send a sp... |
| CVE-2019-4012 | CRITICAL | 9.8 | 2.1% | Apr 15, 2019 | IBM BigFix WebUI Profile Management 6 and Software Distribution 23 is vulnerable to SQL injection. A remote attacker cou... |
| CVE-2019-11236 | — | — | 2.1% | Apr 15, 2019 | In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parame... |
| CVE-2019-0232 | — | — | 99.7% | Apr 15, 2019 | When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 ... |
| CVE-2019-6526 | CRITICAL | 9.8 | 1.0% | Apr 15, 2019 | Moxa IKS-G6824A series Versions 4.5 and prior, EDS-405A series Version 3.8 and prior, EDS-408A series Version 3.8 and pr... |
| CVE-2019-3891 | HIGH | 7.8 | 0.7% | Apr 15, 2019 | It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the cr... |
| CVE-2019-11229 | HIGH | 8.8 | 55.6% | Apr 15, 2019 | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem... |
| CVE-2019-11228 | — | — | 1.3% | Apr 15, 2019 | repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling S... |
| CVE-2019-11222 | HIGH | 7.8 | 1.4% | Apr 15, 2019 | gf_bin128_parse in utils/os_divers.c in GPAC 0.7.1 has a buffer overflow issue for the crypt feature when encountering a... |
| CVE-2019-11221 | — | — | 1.1% | Apr 15, 2019 | GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c. |
| CVE-2019-10880 | CRITICAL | 9.8 | 8.5% | Apr 12, 2019 | Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user... |
| CVE-2019-1574 | — | — | 0.6% | Apr 12, 2019 | Cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition Migration tool 1.1.12 and earlier may allow an... |
| CVE-2019-11213 | — | — | 2.8% | Apr 12, 2019 | In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof se... |
| CVE-2019-11196 | — | — | 6.3% | Apr 12, 2019 | An authentication bypass vulnerability in all versions of ValuePLUS Integrated University Management System (IUMS) allow... |
| CVE-2019-11191 | — | — | 0.5% | Apr 12, 2019 | The Linux kernel through 5.0.7, when CONFIG_IA32_AOUT is enabled and ia32_aout is loaded, allows local users to bypass A... |
| CVE-2019-11190 | — | — | 0.5% | Apr 12, 2019 | The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_... |
| CVE-2019-6534 | HIGH | 7.8 | 1.5% | Apr 11, 2019 | The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0,... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now