2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1723 | CRITICAL | 9.8 | 5.8% | Mar 13, 2019 | A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker t... |
| CVE-2019-9641 | CRITICAL | 9.8 | 9.4% | Mar 9, 2019 | An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. There i... |
| CVE-2019-8275 | CRITICAL | 9.8 | 4.0% | Mar 8, 2019 | UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which result in out-of... |
| CVE-2019-8274 | CRITICAL | 9.8 | 8.3% | Mar 8, 2019 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer offer handler, w... |
| CVE-2019-8273 | CRITICAL | 9.8 | 8.3% | Mar 8, 2019 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer request handler,... |
| CVE-2019-8272 | CRITICAL | 9.8 | 3.9% | Mar 8, 2019 | UltraVNC revision 1211 has multiple off-by-one vulnerabilities in VNC server code, which can potentially result in code ... |
| CVE-2019-8271 | CRITICAL | 9.8 | 8.3% | Mar 8, 2019 | UltraVNC revision 1211 has a heap buffer overflow vulnerability in VNC server code inside file transfer handler, which c... |
| CVE-2019-8268 | CRITICAL | 9.8 | 3.9% | Mar 8, 2019 | UltraVNC revision 1206 has multiple off-by-one vulnerabilities in VNC client code connected with improper usage of Clien... |
| CVE-2019-9636 | CRITICAL | 9.8 | 8.8% | Mar 8, 2019 | Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorre... |
| CVE-2019-1003034 | CRITICAL | 9.9 | 3.0% | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javapos... |
| CVE-2019-1003032 | CRITICAL | 9.9 | 2.5% | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Email Extension Plugin 2.64 and earlier in pom.xml, src/main/java/hudso... |
| CVE-2019-1003031 | CRITICAL | 9.9 | 3.4% | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson... |
| CVE-2019-1003030 | CRITICAL | 9.9 | 76.0% | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/... |
| CVE-2019-1003029 | CRITICAL | 9.9 | 74.3% | Mar 8, 2019 | A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/... |
| CVE-2019-5019 | CRITICAL | 9.8 | 2.3% | Mar 7, 2019 | A heap-based overflow vulnerability exists in the PowerPoint document conversion function of Rainbow PDF Office Server D... |
| CVE-2019-0604 | CRITICAL | 9.8 | 99.9% | Mar 5, 2019 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup ... |
| CVE-2019-3922 | CRITICAL | 9.8 | 5.2% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via ... |
| CVE-2019-3918 | CRITICAL | 9.8 | 2.0% | Mar 5, 2019 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for ... |
| CVE-2019-6563 | CRITICAL | 9.8 | 1.7% | Mar 5, 2019 | Moxa IKS and EDS generate a predictable cookie calculated with an MD5 hash, allowing an attacker to capture the administ... |
| CVE-2019-6557 | CRITICAL | 9.8 | 5.0% | Mar 5, 2019 | Several buffer overflow vulnerabilities have been identified in Moxa IKS and EDS, which may allow remote code execution. |
| CVE-2019-6524 | CRITICAL | 9.8 | 2.7% | Mar 5, 2019 | Moxa IKS and EDS do not implement sufficient measures to prevent multiple failed authentication attempts, which may allo... |
| CVE-2019-6522 | CRITICAL | 9.1 | 2.5% | Mar 5, 2019 | Moxa IKS and EDS fails to properly check array bounds which may allow an attacker to read device memory on arbitrary add... |
| CVE-2019-4032 | CRITICAL | 9.8 | 1.6% | Mar 5, 2019 | IBM Financial Transaction Manager for Digital Payments for Multi-Platform 3.1.0 is vulnerable to SQL injection. A remote... |
| CVE-2019-8262 | CRITICAL | 9.8 | 4.8% | Mar 5, 2019 | UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which ... |
| CVE-2019-8258 | CRITICAL | 9.8 | 4.4% | Mar 5, 2019 | UltraVNC revision 1198 has a heap buffer overflow vulnerability in VNC client code which results code execution. This at... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now