2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10843 | — | — | — | Apr 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-11065 | MEDIUM | 5.9 | 1.4% | Apr 10, 2019 | Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or Coff... |
| CVE-2019-1573 | LOW | 2.5 | 0.3% | Apr 9, 2019 | GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticat... |
| CVE-2019-9696 | — | — | 1.1% | Apr 9, 2019 | Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a ty... |
| CVE-2019-8456 | MEDIUM | 5.9 | 20.4% | Apr 9, 2019 | Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the in... |
| CVE-2019-6140 | CRITICAL | 9.8 | 1.4% | Apr 9, 2019 | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnera... |
| CVE-2019-5585 | — | — | 0.4% | Apr 9, 2019 | An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application'... |
| CVE-2019-3842 | HIGH | 7 | 1.2% | Apr 9, 2019 | In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t... |
| CVE-2019-0879 | — | — | 9.8% | Apr 9, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0877 | — | — | 4.9% | Apr 9, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0876 | MEDIUM | 5.5 | 1.6% | Apr 9, 2019 | An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo... |
| CVE-2019-0875 | — | — | 3.0% | Apr 9, 2019 | An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissio... |
| CVE-2019-0874 | — | — | 2.0% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu... |
| CVE-2019-0871 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0870 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0869 | — | — | 2.0% | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azu... |
| CVE-2019-0868 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0867 | — | — | 2.4% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0866 | — | — | 2.6% | Apr 9, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa... |
| CVE-2019-0862 | — | — | 11.1% | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-0861 | — | — | 11.1% | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-0860 | — | — | 10.8% | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-0859 | HIGH | 7.8 | 4.2% | Apr 9, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2019-0858 | MEDIUM | 6.1 | 2.1% | Apr 9, 2019 | A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ... |
| CVE-2019-0857 | — | — | 3.9% | Apr 9, 2019 | A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now