2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3880 | MEDIUM | 5.4 | 3.4% | Apr 9, 2019 | A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivilege... |
| CVE-2019-3870 | MEDIUM | 6.1 | 0.6% | Apr 9, 2019 | A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation... |
| CVE-2019-3795 | MEDIUM | 5.3 | 1.9% | Apr 9, 2019 | Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure rand... |
| CVE-2019-10244 | — | — | 1.8% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and t... |
| CVE-2019-10243 | — | — | 1.3% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used... |
| CVE-2019-10242 | — | — | 2.0% | Apr 9, 2019 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially a... |
| CVE-2019-11028 | — | — | 2.7% | Apr 9, 2019 | GAT-Ship Web Module before 1.40 suffers from a vulnerability allowing authenticated attackers to upload any file type to... |
| CVE-2019-10634 | — | — | 0.8% | Apr 9, 2019 | An XSS vulnerability in the Zyxel NAS 326 version 5.21 and below allows a remote authenticated attacker to inject arbitr... |
| CVE-2019-10633 | — | — | 3.3% | Apr 9, 2019 | An eval injection vulnerability in the Python web server routing on the Zyxel NAS 326 version 5.21 and below allows a re... |
| CVE-2019-10632 | — | — | 1.4% | Apr 9, 2019 | A directory traversal vulnerability in the file browser component on the Zyxel NAS 326 version 5.21 and below allows a l... |
| CVE-2019-10631 | — | — | 2.3% | Apr 9, 2019 | Shell Metacharacter Injection in the package installer on Zyxel NAS 326 version 5.21 and below allows an authenticated a... |
| CVE-2019-10630 | — | — | 1.2% | Apr 9, 2019 | A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin... |
| CVE-2019-10903 | HIGH | 7.5 | 5.6% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in... |
| CVE-2019-10902 | — | — | 4.7% | Apr 9, 2019 | In Wireshark 3.0.0, the TSDNS dissector could crash. This was addressed in epan/dissectors/packet-tsdns.c by splitting s... |
| CVE-2019-10901 | HIGH | 7.5 | 5.6% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash. This was addressed in epan/diss... |
| CVE-2019-10900 | — | — | 4.5% | Apr 9, 2019 | In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c b... |
| CVE-2019-10899 | HIGH | 7.5 | 5.6% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash. This was addressed in epan/di... |
| CVE-2019-10898 | — | — | 4.5% | Apr 9, 2019 | In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gsm_... |
| CVE-2019-10897 | — | — | 4.6% | Apr 9, 2019 | In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop. This was addressed in epan/dissectors/pack... |
| CVE-2019-10896 | HIGH | 7.5 | 5.7% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/disse... |
| CVE-2019-10895 | HIGH | 7.5 | 5.8% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the NetScaler file parser could crash. This was addressed in wi... |
| CVE-2019-10894 | HIGH | 7.5 | 5.6% | Apr 9, 2019 | In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/d... |
| CVE-2019-0821 | — | — | 6.2% | Apr 9, 2019 | An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Win... |
| CVE-2019-0816 | — | — | 1.4% | Apr 9, 2019 | A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images ... |
| CVE-2019-0809 | — | — | 10.6% | Apr 9, 2019 | A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now