2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9053 | — | — | 56.0% | Mar 26, 2019 | An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve... |
| CVE-2019-7646 | — | — | 7.2% | Mar 26, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package... |
| CVE-2019-9764 | — | — | 0.6% | Mar 26, 2019 | HashiCorp Consul 1.4.3 lacks server hostname verification for agent-to-agent TLS communication. In other words, the prod... |
| CVE-2019-10063 | — | — | 1.9% | Mar 26, 2019 | Flatpak before 1.0.8, 1.1.x and 1.2.x before 1.2.4, and 1.3.x before 1.3.1 allows a sandbox bypass. Flatpak versions sin... |
| CVE-2019-8981 | — | — | 2.7% | Mar 26, 2019 | tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because t... |
| CVE-2019-7715 | — | — | 1.5% | Mar 26, 2019 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell ha... |
| CVE-2019-7714 | — | — | 2.1% | Mar 26, 2019 | An issue was discovered in Interpeak IPWEBS on Green Hills INTEGRITY RTOS 5.0.4. It allocates 60 bytes for the HTTP Auth... |
| CVE-2019-7713 | — | — | 1.9% | Mar 26, 2019 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. There is a heap-b... |
| CVE-2019-7712 | — | — | 1.5% | Mar 26, 2019 | An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RT... |
| CVE-2019-7711 | — | — | 1.5% | Mar 26, 2019 | An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented ... |
| CVE-2019-10061 | — | — | 4.2% | Mar 26, 2019 | utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection.... |
| CVE-2019-10060 | — | — | 1.7% | Mar 26, 2019 | The Verix Multi-app Conductor application 2.7 for Verifone Verix suffers from a buffer overflow vulnerability that allow... |
| CVE-2019-7642 | HIGH | 7.5 | 2.6% | Mar 25, 2019 | D-Link routers with the mydlink feature have some web interfaces without authentication requirements. An attacker can re... |
| CVE-2019-6538 | MEDIUM | 6.5 | 0.8% | Mar 25, 2019 | The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor v... |
| CVE-2019-0204 | HIGH | 7.8 | 2.7% | Mar 25, 2019 | A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container ru... |
| CVE-2019-10044 | — | — | 3.3% | Mar 25, 2019 | Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to a... |
| CVE-2019-7613 | HIGH | 7.5 | 1.3% | Mar 25, 2019 | Winlogbeat versions before 5.6.16 and 6.6.2 had an insufficient logging flaw. An attacker able to inject certain charact... |
| CVE-2019-7612 | CRITICAL | 9.8 | 2.4% | Mar 25, 2019 | A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If ... |
| CVE-2019-7611 | HIGH | 8.1 | 2.1% | Mar 25, 2019 | A permission issue was found in Elasticsearch versions before 5.6.15 and 6.6.1 when Field Level Security and Document Le... |
| CVE-2019-7610 | — | — | 3.9% | Mar 25, 2019 | Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance... |
| CVE-2019-7609 | CRITICAL | 10 | 95.3% | Mar 25, 2019 | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker... |
| CVE-2019-7608 | — | — | 1.3% | Mar 25, 2019 | Kibana versions before 5.6.15 and 6.6.1 had a cross-site scripting (XSS) vulnerability that could allow an attacker to o... |
| CVE-2019-4046 | HIGH | 7.5 | 3.2% | Mar 25, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by improper handlin... |
| CVE-2019-3879 | HIGH | 8.1 | 1.9% | Mar 25, 2019 | It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal com... |
| CVE-2019-3874 | MEDIUM | 6.5 | 1.8% | Mar 25, 2019 | The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now