2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7171 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7170 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7169 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7168 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-3807 | LOW | 3.7 | 0.4% | Jan 29, 2019 | An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of response... |
| CVE-2019-3806 | HIGH | 8.1 | 1.5% | Jan 29, 2019 | An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied ... |
| CVE-2019-7160 | — | — | 3.4% | Jan 29, 2019 | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php,... |
| CVE-2019-7156 | — | — | 1.3% | Jan 29, 2019 | In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero. |
| CVE-2019-7154 | MEDIUM | 6.5 | 1.1% | Jan 29, 2019 | The main function in tools/wasm2js.cpp in Binaryen 1.38.22 has a heap-based buffer overflow because Emscripten is misuse... |
| CVE-2019-7153 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A NULL pointer dereference was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (when c... |
| CVE-2019-7152 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A heap-based buffer over-read was discovered in wasm::WasmBinaryBuilder::processFunctions() in wasm/wasm-binary.cpp (whe... |
| CVE-2019-7151 | MEDIUM | 6.5 | 1.2% | Jan 29, 2019 | A NULL pointer dereference was discovered in wasm::Module::getFunctionOrNull in wasm/wasm.cpp in Binaryen 1.38.22. A cra... |
| CVE-2019-7150 | MEDIUM | 5.5 | 1.4% | Jan 29, 2019 | An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32... |
| CVE-2019-7149 | — | — | 2.2% | Jan 29, 2019 | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0... |
| CVE-2019-7148 | — | — | 1.6% | Jan 29, 2019 | An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfu... |
| CVE-2019-7147 | — | — | 0.8% | Jan 29, 2019 | A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted ... |
| CVE-2019-7146 | — | — | 1.5% | Jan 29, 2019 | In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attacke... |
| CVE-2019-3462 | HIGH | 8.1 | 14.6% | Jan 28, 2019 | Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to co... |
| CVE-2019-6992 | — | — | 0.9% | Jan 28, 2019 | A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker t... |
| CVE-2019-6991 | — | — | 3.3% | Jan 28, 2019 | A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder... |
| CVE-2019-6990 | — | — | 0.7% | Jan 28, 2019 | A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to exec... |
| CVE-2019-3593 | HIGH | 7.5 | 0.3% | Jan 28, 2019 | Exploitation of Privilege/Trust vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0... |
| CVE-2019-6988 | — | — | 1.7% | Jan 28, 2019 | An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive ... |
| CVE-2019-6986 | — | — | 3.0% | Jan 28, 2019 | SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leadi... |
| CVE-2019-3815 | LOW | 3.3 | 0.4% | Jan 28, 2019 | A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now