2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10692 | CRITICAL | 9.8 | 78.7% | Apr 2, 2019 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize... |
| CVE-2019-5891 | CRITICAL | 9.8 | 1.6% | Apr 1, 2019 | An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to ob... |
| CVE-2019-10661 | CRITICAL | 9.8 | 1.8% | Mar 30, 2019 | On Grandstream GXV3611IR_HD before 1.0.3.23 devices, the root account lacks a password. |
| CVE-2019-10655 | CRITICAL | 9.8 | 15.4% | Mar 30, 2019 | Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.... |
| CVE-2019-9918 | CRITICAL | 9.1 | 1.3% | Mar 29, 2019 | An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Input does not get validated and queries... |
| CVE-2019-10269 | CRITICAL | 9.8 | 2.9% | Mar 29, 2019 | BWA (aka Burrow-Wheeler Aligner) before 2019-01-23 has a stack-based buffer overflow in the bns_restore function in bnts... |
| CVE-2019-9204 | CRITICAL | 9.8 | 19.7% | Mar 28, 2019 | SQL injection vulnerability in Nagios IM (component of Nagios XI) before 2.2.7 allows attackers to execute arbitrary SQL... |
| CVE-2019-9203 | CRITICAL | 9.8 | 20.4% | Mar 28, 2019 | Authorization bypass in Nagios IM (component of Nagios XI) before 2.2.7 allows closing incidents in IM via the API. |
| CVE-2019-9165 | CRITICAL | 9.8 | 5.3% | Mar 28, 2019 | SQL injection vulnerability in Nagios XI before 5.5.11 allows attackers to execute arbitrary SQL commands via the API wh... |
| CVE-2019-1003041 | CRITICAL | 9.8 | 3.3% | Mar 28, 2019 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary ... |
| CVE-2019-1003040 | CRITICAL | 9.8 | 3.3% | Mar 28, 2019 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary c... |
| CVE-2019-0160 | CRITICAL | 9.8 | 1.3% | Mar 27, 2019 | Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privile... |
| CVE-2019-1010257 | CRITICAL | 9.1 | 4.4% | Mar 27, 2019 | An Information Disclosure / Data Modification issue exists in article2pdf_getfile.php in the article2pdf Wordpress plugi... |
| CVE-2019-5420 | CRITICAL | 9.8 | 92.1% | Mar 27, 2019 | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th... |
| CVE-2019-10125 | CRITICAL | 9.8 | 5.3% | Mar 27, 2019 | An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_... |
| CVE-2019-6569 | CRITICAL | 9.1 | 1.3% | Mar 26, 2019 | The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into t... |
| CVE-2019-10068 | CRITICAL | 9.8 | 96.0% | Mar 26, 2019 | An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions... |
| CVE-2019-7612 | CRITICAL | 9.8 | 2.4% | Mar 25, 2019 | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If ... |
| CVE-2019-7609 | CRITICAL | 10 | 95.3% | Mar 25, 2019 | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker... |
| CVE-2019-3396 | CRITICAL | 9.8 | 99.9% | Mar 25, 2019 | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers... |
| CVE-2019-9948 | CRITICAL | 9.1 | 11.8% | Mar 23, 2019 | urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypas... |
| CVE-2019-7238 | CRITICAL | 9.8 | 76.5% | Mar 21, 2019 | Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control. |
| CVE-2019-3859 | CRITICAL | 9.1 | 6.3% | Mar 21, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req... |
| CVE-2019-9775 | CRITICAL | 9.1 | 3.0% | Mar 14, 2019 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_C... |
| CVE-2019-9774 | CRITICAL | 9.1 | 3.0% | Mar 14, 2019 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at b... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now