2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7296 | — | — | 1.7% | Jan 31, 2019 | typora through 0.9.64 has XSS, with resultant remote command execution, during inline rendering of a mathematical formul... |
| CVE-2019-7295 | — | — | 1.7% | Jan 31, 2019 | typora through 0.9.63 has XSS, with resultant remote command execution, during block rendering of a mathematical formula... |
| CVE-2019-7283 | HIGH | 7.4 | 2.0% | Jan 31, 2019 | An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories ... |
| CVE-2019-7282 | MEDIUM | 5.9 | 2.1% | Jan 31, 2019 | In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the... |
| CVE-2019-6111 | MEDIUM | 5.9 | 58.2% | Jan 31, 2019 | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh... |
| CVE-2019-6110 | MEDIUM | 6.8 | 20.9% | Jan 31, 2019 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T... |
| CVE-2019-6109 | MEDIUM | 6.8 | 3.8% | Jan 31, 2019 | An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (o... |
| CVE-2019-4040 | MEDIUM | 6.1 | 1.3% | Jan 31, 2019 | IBM I 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c... |
| CVE-2019-7250 | — | — | 0.8% | Jan 31, 2019 | An issue was discovered in the Cross Reference Add-on 36 for Google Docs. Stored XSS in the preview boxes in the configu... |
| CVE-2019-7249 | — | — | 2.5% | Jan 31, 2019 | In Keybase before 2.12.6 on macOS, the move RPC to the Helper was susceptible to time-to-check-time-to-use bugs and woul... |
| CVE-2019-7216 | — | — | 2.0% | Jan 31, 2019 | An issue was discovered in FileChucker 4.99e-free-e02. filechucker.cgi has a filter bypass that allows a malicious user ... |
| CVE-2019-6438 | — | — | 2.3% | Jan 31, 2019 | SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. |
| CVE-2019-0190 | HIGH | 7.5 | 59.9% | Jan 30, 2019 | A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request ... |
| CVE-2019-7237 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=... |
| CVE-2019-7236 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManage... |
| CVE-2019-7235 | — | — | 2.5% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../... |
| CVE-2019-7234 | — | — | 2.2% | Jan 30, 2019 | An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../... |
| CVE-2019-7233 | — | — | 1.5% | Jan 30, 2019 | In libdoc through 2019-01-28, doc2text in catdoc.c has a NULL pointer dereference. |
| CVE-2019-3913 | MEDIUM | 4.9 | 1.7% | Jan 30, 2019 | Command manipulation in LabKey Server Community Edition before 18.3.0-61806.763 allows an authenticated remote attacker ... |
| CVE-2019-3912 | MEDIUM | 6.1 | 4.8% | Jan 30, 2019 | An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL param... |
| CVE-2019-3911 | MEDIUM | 6.1 | 3.8% | Jan 30, 2019 | Reflected cross-site scripting (XSS) vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 allows an ... |
| CVE-2019-1566 | MEDIUM | 6.1 | 1.2% | Jan 30, 2019 | The PAN-OS management web interface in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlie... |
| CVE-2019-1565 | — | — | 0.7% | Jan 30, 2019 | The PAN-OS external dynamics lists in PAN-OS 7.1.21 and earlier, PAN-OS 8.0.14 and earlier, and PAN-OS 8.1.5 and earlier... |
| CVE-2019-7173 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7172 | — | — | 0.9% | Jan 29, 2019 | A stored-self XSS exists in ATutor through v2.2.4, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now