2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7006 | MEDIUM | 5.5 | 0.3% | Feb 27, 2019 | Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a lo... |
| CVE-2019-9201 | CRITICAL | 9.8 | 3.1% | Feb 26, 2019 | Multiple Phoenix Contact devices allow remote attackers to establish TCP sessions to port 1962 and obtain sensitive info... |
| CVE-2019-9200 | — | — | 3.5% | Feb 26, 2019 | A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for exa... |
| CVE-2019-9199 | — | — | 2.6% | Feb 26, 2019 | PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can ... |
| CVE-2019-9195 | CRITICAL | 9.8 | 3.6% | Feb 26, 2019 | util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory t... |
| CVE-2019-9194 | — | — | 96.6% | Feb 26, 2019 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. |
| CVE-2019-9192 | — | — | 2.4% | Feb 26, 2019 | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled ... |
| CVE-2019-9191 | — | — | 1.5% | Feb 26, 2019 | The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secre... |
| CVE-2019-7392 | — | — | 1.7% | Feb 26, 2019 | An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a re... |
| CVE-2019-9184 | — | — | 9.0% | Feb 26, 2019 | SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr... |
| CVE-2019-6595 | — | — | 0.9% | Feb 26, 2019 | Cross-site scripting (XSS) vulnerability in F5 BIG-IP Access Policy Manager (APM) 11.5.x and 11.6.x Admin Web UI. |
| CVE-2019-6594 | — | — | 1.0% | Feb 26, 2019 | On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not ... |
| CVE-2019-6593 | — | — | 0.7% | Feb 26, 2019 | On BIG-IP 11.5.1-11.5.4, 11.6.1, and 12.1.0, a virtual server configured with a Client SSL profile may be vulnerable to ... |
| CVE-2019-6592 | — | — | 1.0% | Feb 26, 2019 | On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or ser... |
| CVE-2019-9182 | — | — | 0.8% | Feb 26, 2019 | There is a CSRF in ZZZCMS zzzphp V1.6.1 via a /admin015/save.php?act=editfile request. It allows PHP code injection by p... |
| CVE-2019-9181 | — | — | 2.0% | Feb 26, 2019 | SchoolCMS version 2.3.1 allows file upload via the logo upload feature at admin.php?m=admin&c=site&a=save by using the .... |
| CVE-2019-9169 | CRITICAL | 9.8 | 4.7% | Feb 26, 2019 | In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer ove... |
| CVE-2019-9168 | — | — | 1.0% | Feb 26, 2019 | WooCommerce before 3.5.5 allows XSS via a Photoswipe caption. |
| CVE-2019-9162 | HIGH | 7.8 | 1.1% | Feb 25, 2019 | In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient ... |
| CVE-2019-6266 | — | — | 1.2% | Feb 25, 2019 | Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and ... |
| CVE-2019-6265 | — | — | 0.6% | Feb 25, 2019 | The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 ar... |
| CVE-2019-9152 | — | — | 1.5% | Feb 25, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5MM_xstrdup in H... |
| CVE-2019-9151 | — | — | 1.6% | Feb 25, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5VM_memcpyvv in ... |
| CVE-2019-9146 | — | — | 0.8% | Feb 25, 2019 | Jamf Self Service 10.9.0 allows man-in-the-middle attackers to obtain a root shell by leveraging the "publish Bash shell... |
| CVE-2019-9145 | — | — | 0.8% | Feb 25, 2019 | An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now