2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7395 | HIGH | 7.5 | 3.4% | Feb 5, 2019 | In ImageMagick before 7.0.8-25, a memory leak exists in WritePSDChannel in coders/psd.c. |
| CVE-2019-7390 | — | — | 2.0% | Feb 5, 2019 | An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access cont... |
| CVE-2019-7389 | — | — | 2.7% | Feb 5, 2019 | An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access ... |
| CVE-2019-7388 | — | — | 2.8% | Feb 5, 2019 | An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access cont... |
| CVE-2019-7387 | — | — | 1.4% | Feb 4, 2019 | A local file inclusion vulnerability exists in the web interface of Systrome Cumilon ISG-600C, ISG-600H, and ISG-800W 1.... |
| CVE-2019-4038 | MEDIUM | 6.2 | 0.4% | Feb 4, 2019 | IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the ap... |
| CVE-2019-1000024 | — | — | 1.2% | Feb 4, 2019 | OPT/NET BV NG-NetMS version v3.6-2 and earlier versions contains a Cross Site Scripting (XSS) vulnerability in /js/libs/... |
| CVE-2019-1000023 | — | — | 2.1% | Feb 4, 2019 | OPT/NET BV OPTOSS Next Gen Network Management System (NG-NetMS) version v3.6-2 and earlier versions contains a SQL Injec... |
| CVE-2019-1000022 | — | — | 0.6% | Feb 4, 2019 | Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket h... |
| CVE-2019-1000021 | — | — | 2.3% | Feb 4, 2019 | slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerabilit... |
| CVE-2019-1000020 | MEDIUM | 6.5 | 3.2% | Feb 4, 2019 | libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: ... |
| CVE-2019-1000019 | MEDIUM | 6.5 | 3.4% | Feb 4, 2019 | libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: ... |
| CVE-2019-1000018 | HIGH | 7.8 | 1.9% | Feb 4, 2019 | rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'... |
| CVE-2019-1000017 | — | — | 1.0% | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component t... |
| CVE-2019-1000016 | — | — | 1.1% | Feb 4, 2019 | FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can... |
| CVE-2019-1000015 | — | — | 0.8% | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_... |
| CVE-2019-1000014 | — | — | 1.8% | Feb 4, 2019 | Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification t... |
| CVE-2019-1000013 | — | — | 0.9% | Feb 4, 2019 | Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verif... |
| CVE-2019-1000012 | — | — | 0.9% | Feb 4, 2019 | Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verificati... |
| CVE-2019-1000011 | — | — | 1.0% | Feb 4, 2019 | API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations ... |
| CVE-2019-1000010 | — | — | 0.9% | Feb 4, 2019 | phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can... |
| CVE-2019-1000009 | — | — | 1.3% | Feb 4, 2019 | Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Direct... |
| CVE-2019-1000008 | — | — | 1.5% | Feb 4, 2019 | All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restric... |
| CVE-2019-1000007 | — | — | 1.2% | Feb 4, 2019 | aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, r... |
| CVE-2019-1000006 | CRITICAL | 9.8 | 1.6% | Feb 4, 2019 | RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in s... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now