2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5927 | — | — | 3.0% | Mar 27, 2019 | Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrar... |
| CVE-2019-5926 | — | — | 1.5% | Mar 27, 2019 | Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject ar... |
| CVE-2019-5420 | CRITICAL | 9.8 | 92.1% | Mar 27, 2019 | A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th... |
| CVE-2019-5419 | HIGH | 7.5 | 8.7% | Mar 27, 2019 | There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where... |
| CVE-2019-5418 | HIGH | 7.5 | 98.5% | Mar 27, 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe... |
| CVE-2019-3877 | MEDIUM | 5.8 | 2.1% | Mar 27, 2019 | A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with bac... |
| CVE-2019-3847 | MEDIUM | 4.8 | 2.3% | Mar 27, 2019 | A vulnerability was found in moodle before versions 3.6.3, 3.5.5, 3.4.8 and 3.1.17. Users with the "login as other users... |
| CVE-2019-3840 | MEDIUM | 5.8 | 1.5% | Mar 27, 2019 | A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information ... |
| CVE-2019-3828 | MEDIUM | 4.2 | 0.5% | Mar 27, 2019 | Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and o... |
| CVE-2019-3821 | HIGH | 7.5 | 2.9% | Mar 27, 2019 | A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthentic... |
| CVE-2019-3817 | HIGH | 7.5 | 1.7% | Mar 27, 2019 | A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacke... |
| CVE-2019-3814 | HIGH | 7.7 | 2.5% | Mar 27, 2019 | It was discovered that Dovecot before versions 2.2.36.1 and 2.3.4.1 incorrectly handled client certificates. A remote at... |
| CVE-2019-9917 | — | — | 3.1% | Mar 27, 2019 | ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. |
| CVE-2019-10125 | CRITICAL | 9.8 | 5.3% | Mar 27, 2019 | An issue was discovered in aio_poll() in fs/aio.c in the Linux kernel through 5.0.4. A file may be released by aio_poll_... |
| CVE-2019-10124 | — | — | — | Mar 27, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-10118 | — | — | 0.8% | Mar 27, 2019 | Snipe-IT before 4.6.14 has XSS, as demonstrated by log_meta values and the user's last name in the API. |
| CVE-2019-7167 | — | — | 1.7% | Mar 27, 2019 | Zcash, before the Sapling network upgrade (2018-10-28), had a counterfeiting vulnerability. A key-generation process, du... |
| CVE-2019-1571 | — | — | 1.1% | Mar 26, 2019 | The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ... |
| CVE-2019-6569 | CRITICAL | 9.1 | 1.3% | Mar 26, 2019 | The monitor barrier of the affected products insufficiently blocks data from being forwarded over the mirror port into t... |
| CVE-2019-1572 | — | — | 2.5% | Mar 26, 2019 | PAN-OS 9.0.0 may allow an unauthenticated remote user to access php files. |
| CVE-2019-1570 | — | — | 1.1% | Mar 26, 2019 | The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ... |
| CVE-2019-1569 | — | — | 1.1% | Mar 26, 2019 | The Expedition Migration tool 1.1.8 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ... |
| CVE-2019-10107 | — | — | 0.7% | Mar 26, 2019 | CMS Made Simple 2.2.10 has XSS via the myaccount.php "Email Address" field, which is reachable via the "My Preferences -... |
| CVE-2019-10106 | — | — | 0.7% | Mar 26, 2019 | CMS Made Simple 2.2.10 has XSS via the 'moduleinterface.php' Name field, which is reachable via an "Add Category" action... |
| CVE-2019-10105 | — | — | 0.7% | Mar 26, 2019 | CMS Made Simple 2.2.10 has a Self-XSS vulnerability via the Layout Design Manager "Name" field, which is reachable via a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now