2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9771 | HIGH | 7.5 | 2.8% | Mar 14, 2019 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_conver... |
| CVE-2019-9770 | HIGH | 7.5 | 2.9% | Mar 14, 2019 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_deco... |
| CVE-2019-9769 | — | — | 2.3% | Mar 14, 2019 | PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad... |
| CVE-2019-9768 | — | — | 11.7% | Mar 14, 2019 | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta... |
| CVE-2019-9767 | — | — | 8.0% | Mar 14, 2019 | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ... |
| CVE-2019-9766 | — | — | 8.0% | Mar 14, 2019 | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ... |
| CVE-2019-9765 | — | — | 0.9% | Mar 14, 2019 | In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, ... |
| CVE-2019-9762 | — | — | 5.1% | Mar 14, 2019 | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnera... |
| CVE-2019-9761 | — | — | 1.7% | Mar 14, 2019 | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network... |
| CVE-2019-9760 | — | — | 53.1% | Mar 14, 2019 | FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont... |
| CVE-2019-9754 | — | — | 0.9% | Mar 13, 2019 | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byt... |
| CVE-2019-9752 | MEDIUM | 5.4 | 1.1% | Mar 13, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4.... |
| CVE-2019-9751 | — | — | 0.8% | Mar 13, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is ... |
| CVE-2019-6601 | MEDIUM | 5.5 | 0.3% | Mar 13, 2019 | In BIG-IP 13.0.0, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, the Application Acceleration Manager (AAM) wamd pr... |
| CVE-2019-6600 | MEDIUM | 6.1 | 1.2% | Mar 13, 2019 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.3, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when remote authenticati... |
| CVE-2019-6599 | — | — | 0.8% | Mar 13, 2019 | In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed p... |
| CVE-2019-6598 | — | — | 1.1% | Mar 13, 2019 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1... |
| CVE-2019-6597 | — | — | 1.3% | Mar 13, 2019 | In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenti... |
| CVE-2019-6596 | — | — | 1.4% | Mar 13, 2019 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragment... |
| CVE-2019-3785 | HIGH | 8.1 | 1.3% | Mar 13, 2019 | Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote auth... |
| CVE-2019-3716 | HIGH | 7.8 | 0.4% | Mar 13, 2019 | RSA Archer versions, prior to 6.5 SP2, contain an information exposure vulnerability. The database connection password m... |
| CVE-2019-3715 | HIGH | 7.8 | 0.3% | Mar 13, 2019 | RSA Archer versions, prior to 6.5 SP1, contain an information exposure vulnerability. Users' session information is logg... |
| CVE-2019-3711 | MEDIUM | 5.8 | 2.0% | Mar 13, 2019 | RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious... |
| CVE-2019-1723 | CRITICAL | 9.8 | 5.8% | Mar 13, 2019 | A vulnerability in the Cisco Common Services Platform Collector (CSPC) could allow an unauthenticated, remote attacker t... |
| CVE-2019-9750 | — | — | 1.3% | Mar 13, 2019 | In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now