2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0680 | — | — | 8.1% | Apr 9, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-0678 | — | — | 6.1% | Apr 9, 2019 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, whic... |
| CVE-2019-11026 | MEDIUM | 6.5 | 1.8% | Apr 8, 2019 | FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error funct... |
| CVE-2019-11025 | MEDIUM | 5.4 | 1.3% | Apr 8, 2019 | In clearFilter() in utilities.php in Cacti before 1.2.3, no escaping occurs before printing out the value of the SNMP co... |
| CVE-2019-11024 | — | — | 1.0% | Apr 8, 2019 | The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion. |
| CVE-2019-11023 | — | — | 5.0% | Apr 8, 2019 | The agroot() function in cgraph\obj.c in libcgraph.a in Graphviz 2.39.20160612.1140 has a NULL pointer dereference, as d... |
| CVE-2019-0667 | — | — | 31.3% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows... |
| CVE-2019-0666 | — | — | 20.4% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows... |
| CVE-2019-0665 | — | — | 8.3% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows... |
| CVE-2019-0639 | — | — | 12.0% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, ... |
| CVE-2019-0617 | — | — | 19.6% | Apr 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0614 | — | — | 6.6% | Apr 8, 2019 | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its m... |
| CVE-2019-0612 | — | — | 10.5% | Apr 8, 2019 | A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj... |
| CVE-2019-0611 | — | — | 9.2% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-0609 | — | — | 9.8% | Apr 8, 2019 | A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow... |
| CVE-2019-0603 | — | — | 34.2% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in ... |
| CVE-2019-0592 | — | — | 22.9% | Apr 8, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-0211 | HIGH | 7.8 | 65.0% | Apr 8, 2019 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege... |
| CVE-2019-11018 | — | — | 1.4% | Apr 8, 2019 | application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-bas... |
| CVE-2019-11016 | — | — | 1.2% | Apr 8, 2019 | Elgg before 1.12.18 and 2.3.x before 2.3.11 has an open redirect. |
| CVE-2019-0217 | HIGH | 7.5 | 16.6% | Apr 8, 2019 | In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded serve... |
| CVE-2019-1798 | MEDIUM | 5.5 | 1.1% | Apr 8, 2019 | A vulnerability in the Portable Executable (PE) file scanning functionality of Clam AntiVirus (ClamAV) Software versions... |
| CVE-2019-1788 | MEDIUM | 5.5 | 1.8% | Apr 8, 2019 | A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software... |
| CVE-2019-11014 | — | — | 2.3% | Apr 8, 2019 | The VStarCam vstc.vscam.client library and vstc.vscam shared object, as used in the Eye4 application (for Android, iOS, ... |
| CVE-2019-0215 | — | — | 10.5% | Apr 8, 2019 | In Apache HTTP Server 2.4 releases 2.4.37 and 2.4.38, a bug in mod_ssl when using per-location client certificate verifi... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now