2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9749 | HIGH | 7.5 | 1.7% | Mar 13, 2019 | An issue was discovered in the MQTT input plugin in Fluent Bit through 1.0.4. When this plugin acts as an MQTT broker (s... |
| CVE-2019-9748 | — | — | 2.4% | Mar 13, 2019 | In tinysvcmdns through 2018-01-16, an mDNS server processing a crafted packet can perform arbitrary data read operations... |
| CVE-2019-9747 | — | — | 1.4% | Mar 13, 2019 | In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while par... |
| CVE-2019-9746 | — | — | 1.6% | Mar 13, 2019 | In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_... |
| CVE-2019-9742 | — | — | 1.4% | Mar 13, 2019 | gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Char... |
| CVE-2019-9741 | MEDIUM | 6.1 | 2.3% | Mar 13, 2019 | An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, a... |
| CVE-2019-9740 | MEDIUM | 6.1 | 5.4% | Mar 13, 2019 | An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection i... |
| CVE-2019-9738 | — | — | 0.9% | Mar 13, 2019 | jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. |
| CVE-2019-9737 | MEDIUM | 6.1 | 0.9% | Mar 13, 2019 | Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. |
| CVE-2019-9736 | — | — | 0.8% | Mar 13, 2019 | DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. |
| CVE-2019-9735 | — | — | 3.7% | Mar 13, 2019 | An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x bef... |
| CVE-2019-9729 | — | — | 1.0% | Mar 12, 2019 | In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because ... |
| CVE-2019-5925 | — | — | 0.8% | Mar 12, 2019 | Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Pro... |
| CVE-2019-5924 | HIGH | 8.8 | 1.2% | Mar 12, 2019 | Cross-site request forgery (CSRF) vulnerability in Smart Forms 2.6.15 and earlier allows remote attackers to hijack the ... |
| CVE-2019-5923 | — | — | 2.2% | Mar 12, 2019 | Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attacke... |
| CVE-2019-5922 | — | — | 4.6% | Mar 12, 2019 | Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Troj... |
| CVE-2019-5921 | — | — | 4.6% | Mar 12, 2019 | Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unsp... |
| CVE-2019-5920 | — | — | 0.8% | Mar 12, 2019 | Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the aut... |
| CVE-2019-5919 | — | — | 1.0% | Mar 12, 2019 | An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remo... |
| CVE-2019-5918 | — | — | 1.9% | Mar 12, 2019 | Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vec... |
| CVE-2019-5917 | — | — | 21.4% | Mar 12, 2019 | azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service vi... |
| CVE-2019-0277 | — | — | 2.2% | Mar 12, 2019 | SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from... |
| CVE-2019-0276 | — | — | 1.8% | Mar 12, 2019 | Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) perfor... |
| CVE-2019-0275 | MEDIUM | 5.4 | 0.8% | Mar 12, 2019 | SAML 1.1 SSO Demo Application in SAP NetWeaver Java Application Server (J2EE-APPS), versions 7.10 to 7.11, 7.20, 7.30, 7... |
| CVE-2019-0274 | — | — | 2.4% | Mar 12, 2019 | SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or f... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now