2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7560 | — | — | 1.0% | Feb 7, 2019 | In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_... |
| CVE-2019-7559 | — | — | 0.8% | Feb 7, 2019 | In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to ... |
| CVE-2019-7548 | HIGH | 7.8 | 1.8% | Feb 6, 2019 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. |
| CVE-2019-7547 | — | — | 0.7% | Feb 6, 2019 | An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name ... |
| CVE-2019-7546 | — | — | 0.9% | Feb 6, 2019 | An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) v... |
| CVE-2019-7545 | — | — | 0.7% | Feb 6, 2019 | In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability ... |
| CVE-2019-7544 | — | — | 0.7% | Feb 6, 2019 | An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripti... |
| CVE-2019-7543 | — | — | 3.1% | Feb 6, 2019 | In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability. |
| CVE-2019-6517 | MEDIUM | 6.8 | 0.4% | Feb 6, 2019 | BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November ... |
| CVE-2019-3825 | MEDIUM | 6.3 | 0.5% | Feb 6, 2019 | A vulnerability was discovered in gdm before 3.31.4. When timed login is enabled in configuration, an attacker could byp... |
| CVE-2019-3823 | MEDIUM | 4.3 | 4.3% | Feb 6, 2019 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-o... |
| CVE-2019-3822 | CRITICAL | 9.8 | 12.8% | Feb 6, 2019 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an ... |
| CVE-2019-3820 | MEDIUM | 4.3 | 0.5% | Feb 6, 2019 | It was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual action... |
| CVE-2019-3464 | CRITICAL | 9.8 | 4.7% | Feb 6, 2019 | Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restri... |
| CVE-2019-3463 | CRITICAL | 9.8 | 4.9% | Feb 6, 2019 | Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell t... |
| CVE-2019-1003023 | — | — | 1.0% | Feb 6, 2019 | A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/jav... |
| CVE-2019-1003022 | — | — | 0.7% | Feb 6, 2019 | A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows ... |
| CVE-2019-1003021 | — | — | 1.1% | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlie... |
| CVE-2019-1003020 | — | — | 0.6% | Feb 6, 2019 | A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfig... |
| CVE-2019-1003019 | — | — | 0.9% | Feb 6, 2019 | An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm... |
| CVE-2019-1003018 | — | — | 1.1% | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in Gi... |
| CVE-2019-1003017 | — | — | 0.5% | Feb 6, 2019 | A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allow... |
| CVE-2019-1003016 | — | — | 1.0% | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/... |
| CVE-2019-1003015 | — | — | 1.8% | Feb 6, 2019 | An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org... |
| CVE-2019-1003014 | — | — | 0.9% | Feb 6, 2019 | An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resour... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now