2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10732 | MEDIUM | 4.3 | 0.6% | Apr 7, 2019 | In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a craf... |
| CVE-2019-10908 | — | — | 1.6% | Apr 7, 2019 | In Airsonic 10.2.1, RecoverController.java generates passwords via org.apache.commons.lang.RandomStringUtils, which uses... |
| CVE-2019-10907 | — | — | 0.9% | Apr 7, 2019 | Airsonic 10.2.1 uses Spring's default remember-me mechanism based on MD5, with a fixed key of airsonic in GlobalSecurity... |
| CVE-2019-10906 | HIGH | 8.6 | 3.6% | Apr 7, 2019 | In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. |
| CVE-2019-10905 | — | — | 1.5% | Apr 6, 2019 | Parsedown before 1.7.2, when safe mode is used and HTML markup is disabled, might allow attackers to execute arbitrary J... |
| CVE-2019-10904 | — | — | 1.6% | Apr 6, 2019 | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. |
| CVE-2019-9490 | — | — | 1.5% | Apr 5, 2019 | A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized us... |
| CVE-2019-9489 | — | — | 2.3% | Apr 5, 2019 | A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business ... |
| CVE-2019-6554 | HIGH | 7.5 | 1.6% | Apr 5, 2019 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. An improper access control vulnerability may allow an attacker to c... |
| CVE-2019-6552 | CRITICAL | 9.8 | 3.3% | Apr 5, 2019 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple command injection vulnerabilities, caused by a lack of pro... |
| CVE-2019-6550 | CRITICAL | 9.8 | 6.1% | Apr 5, 2019 | Advantech WebAccess/SCADA, Versions 8.3.5 and prior. Multiple stack-based buffer overflow vulnerabilities, caused by a l... |
| CVE-2019-10479 | — | — | 3.8% | Apr 5, 2019 | An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. A hard-coded username and password were... |
| CVE-2019-10478 | — | — | 1.9% | Apr 5, 2019 | An issue was discovered on Glory RBW-100 devices with firmware ISP-K05-02 7.0.0. An unrestricted file upload vulnerabili... |
| CVE-2019-10888 | — | — | 0.6% | Apr 5, 2019 | A CSRF Issue that can add an admin user was discovered in UKcms v1.1.10 via admin.php/admin/role/add.html. |
| CVE-2019-10887 | MEDIUM | 6.1 | 5.8% | Apr 5, 2019 | A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82... |
| CVE-2019-10885 | — | — | 1.0% | Apr 5, 2019 | An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a... |
| CVE-2019-10884 | — | — | 1.2% | Apr 5, 2019 | Uniqkey Password Manager 1.14 contains a vulnerability because it fails to recognize the difference between domains and ... |
| CVE-2019-10875 | MEDIUM | 6.5 | 2.2% | Apr 5, 2019 | A URL spoofing vulnerability was found in all international versions of Xiaomi Mi browser 10.5.6-g (aka the MIUI native ... |
| CVE-2019-10877 | — | — | 2.2% | Apr 5, 2019 | In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in engine/shared/map.cpp that can lead to a buffer over... |
| CVE-2019-10879 | — | — | 5.0% | Apr 5, 2019 | In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead ... |
| CVE-2019-10878 | — | — | 3.9% | Apr 5, 2019 | In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and ... |
| CVE-2019-10876 | — | — | 1.8% | Apr 5, 2019 | An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating... |
| CVE-2019-10874 | — | — | 4.5% | Apr 5, 2019 | Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to ex... |
| CVE-2019-10873 | — | — | 2.6% | Apr 5, 2019 | An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at... |
| CVE-2019-10872 | — | — | 2.7% | Apr 5, 2019 | An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparen... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now