2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3861 | MEDIUM | 5 | 5.1% | Mar 25, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value gre... |
| CVE-2019-3860 | MEDIUM | 5 | 5.1% | Mar 25, 2019 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed... |
| CVE-2019-3857 | HIGH | 8.8 | 6.1% | Mar 25, 2019 | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SS... |
| CVE-2019-3856 | HIGH | 8.8 | 6.1% | Mar 25, 2019 | An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way ... |
| CVE-2019-3838 | MEDIUM | 5.5 | 2.6% | Mar 25, 2019 | It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A ... |
| CVE-2019-3835 | MEDIUM | 5.5 | 2.6% | Mar 25, 2019 | It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A speciall... |
| CVE-2019-3396 | CRITICAL | 9.8 | 99.9% | Mar 25, 2019 | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers... |
| CVE-2019-3395 | — | — | 6.7% | Mar 25, 2019 | The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), f... |
| CVE-2019-10042 | — | — | 1.7% | Mar 25, 2019 | The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th... |
| CVE-2019-10041 | — | — | 1.5% | Mar 25, 2019 | The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th... |
| CVE-2019-10040 | — | — | 2.5% | Mar 25, 2019 | The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th... |
| CVE-2019-10039 | — | — | 1.9% | Mar 25, 2019 | The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get th... |
| CVE-2019-10012 | HIGH | 7.5 | 1.6% | Mar 25, 2019 | Jenzabar JICS (aka Internet Campus Solution) before 9 allows remote attackers to upload and execute arbitrary .aspx code... |
| CVE-2019-10011 | — | — | 2.1% | Mar 25, 2019 | ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attack... |
| CVE-2019-3863 | HIGH | 7.5 | 3.4% | Mar 25, 2019 | A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple... |
| CVE-2019-3841 | HIGH | 7.4 | 0.5% | Mar 25, 2019 | Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when ... |
| CVE-2019-3831 | MEDIUM | 6.7 | 1.0% | Mar 25, 2019 | A vulnerability was discovered in vdsm, version 4.19 through 4.30.3 and 4.30.5 through 4.30.8. The systemd_run function ... |
| CVE-2019-3827 | HIGH | 7 | 0.4% | Mar 25, 2019 | An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modif... |
| CVE-2019-3810 | MEDIUM | 6.1 | 13.9% | Mar 25, 2019 | A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers... |
| CVE-2019-3809 | MEDIUM | 6.5 | 0.9% | Mar 25, 2019 | A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed... |
| CVE-2019-3808 | MEDIUM | 5.4 | 1.1% | Mar 25, 2019 | A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported vers... |
| CVE-2019-6240 | — | — | 2.2% | Mar 25, 2019 | An issue was discovered in GitLab Community and Enterprise Edition before 11.4. It allows Directory Traversal. |
| CVE-2019-3484 | — | — | 1.4% | Mar 25, 2019 | Mitigates a remote code execution issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3483 | — | — | 1.6% | Mar 25, 2019 | Mitigates a potential information leakage issue in ArcSight Logger versions prior to 6.7. |
| CVE-2019-3482 | — | — | 4.2% | Mar 25, 2019 | Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now