2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9946 | — | — | 3.1% | Apr 2, 2019 | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfigurat... |
| CVE-2019-7477 | — | — | 1.2% | Apr 2, 2019 | A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext da... |
| CVE-2019-7475 | CRITICAL | 9.8 | 1.4% | Apr 2, 2019 | A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivi... |
| CVE-2019-7474 | MEDIUM | 6.5 | 0.7% | Apr 2, 2019 | A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unsta... |
| CVE-2019-10692 | CRITICAL | 9.8 | 78.7% | Apr 2, 2019 | In the wp-google-maps plugin before 7.11.18 for WordPress, includes/class.rest-api.php in the REST API does not sanitize... |
| CVE-2019-5524 | — | — | 4.1% | Apr 2, 2019 | VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in ... |
| CVE-2019-5515 | — | — | 4.2% | Apr 2, 2019 | VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates ... |
| CVE-2019-1010260 | — | — | 1.5% | Apr 2, 2019 | Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be co... |
| CVE-2019-9759 | — | — | 1.5% | Apr 2, 2019 | An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/a... |
| CVE-2019-4093 | MEDIUM | 4.4 | 0.3% | Apr 2, 2019 | IBM Tivoli Storage Manager (IBM Spectrum Protect 8.1.7) could allow a user to restore files and directories using IBM Sp... |
| CVE-2019-4080 | MEDIUM | 6.5 | 3.1% | Apr 2, 2019 | IBM WebSphere Application Server Admin Console 7.5, 8.0, 8.5, and 9.0 is vulnerable to a potential denial of service, ca... |
| CVE-2019-4043 | HIGH | 7.1 | 2.5% | Apr 2, 2019 | IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) a... |
| CVE-2019-9193 | — | — | 91.9% | Apr 1, 2019 | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve... |
| CVE-2019-5519 | — | — | 1.0% | Apr 1, 2019 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.... |
| CVE-2019-5518 | — | — | 0.8% | Apr 1, 2019 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.... |
| CVE-2019-5514 | — | — | 3.5% | Apr 1, 2019 | VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessib... |
| CVE-2019-3792 | MEDIUM | 6.8 | 1.1% | Apr 1, 2019 | Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a ... |
| CVE-2019-6715 | HIGH | 7.5 | 19.4% | Apr 1, 2019 | pub/sns.php in the W3 Total Cache plugin before 0.9.4 for WordPress allows remote attackers to read arbitrary files via ... |
| CVE-2019-3489 | — | — | 1.7% | Apr 1, 2019 | An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Mana... |
| CVE-2019-8956 | HIGH | 7.8 | 1.1% | Apr 1, 2019 | In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp... |
| CVE-2019-5523 | — | — | 3.3% | Apr 1, 2019 | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerabilit... |
| CVE-2019-9132 | — | — | 2.3% | Apr 1, 2019 | Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the mess... |
| CVE-2019-10686 | — | — | 1.6% | Apr 1, 2019 | An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intr... |
| CVE-2019-5891 | CRITICAL | 9.8 | 1.6% | Apr 1, 2019 | An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to ob... |
| CVE-2019-5890 | HIGH | 8.8 | 1.8% | Apr 1, 2019 | An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now