2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-3587 | HIGH | 7.2 | 1.4% | Jan 23, 2019 | DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 a... |
| CVE-2019-3584 | HIGH | 7.4 | 0.3% | Jan 23, 2019 | Exploitation of Authentication vulnerability in MVision Endpoint in McAfee MVision Endpoint Prior to 1811 Update 1 (18.1... |
| CVE-2019-6691 | — | — | 1.1% | Jan 23, 2019 | phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related... |
| CVE-2019-6260 | — | — | 3.6% | Jan 22, 2019 | The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-perfor... |
| CVE-2019-6510 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSR... |
| CVE-2019-6509 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows C... |
| CVE-2019-6508 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allow... |
| CVE-2019-6507 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allo... |
| CVE-2019-6339 | — | — | 33.2% | Jan 22, 2019 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulner... |
| CVE-2019-6503 | — | — | 2.2% | Jan 22, 2019 | There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side... |
| CVE-2019-6338 | — | — | 2.3% | Jan 22, 2019 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-par... |
| CVE-2019-1003004 | HIGH | 7.2 | 1.6% | Jan 22, 2019 | An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/ja... |
| CVE-2019-1003003 | HIGH | 7.2 | 1.5% | Jan 22, 2019 | An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/ja... |
| CVE-2019-1003002 | HIGH | 8.8 | 81.6% | Jan 22, 2019 | A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src... |
| CVE-2019-1003001 | HIGH | 8.8 | 86.2% | Jan 22, 2019 | A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins... |
| CVE-2019-1003000 | HIGH | 8.8 | 98.4% | Jan 22, 2019 | A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/... |
| CVE-2019-6502 | — | — | 2.2% | Jan 22, 2019 | sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv. |
| CVE-2019-6500 | — | — | 4.1% | Jan 21, 2019 | In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a ... |
| CVE-2019-6499 | — | — | 1.5% | Jan 21, 2019 | Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint databas... |
| CVE-2019-6498 | — | — | 5.0% | Jan 21, 2019 | GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused. |
| CVE-2019-6497 | — | — | 1.0% | Jan 20, 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter. |
| CVE-2019-6496 | — | — | 6.6% | Jan 20, 2019 | The ThreadX-based firmware on Marvell Avastar Wi-Fi devices, models 88W8787, 88W8797, 88W8801, 88W8897, and 88W8997, all... |
| CVE-2019-3774 | CRITICAL | 9.8 | 3.0% | Jan 18, 2019 | Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injec... |
| CVE-2019-3773 | CRITICAL | 9.8 | 4.1% | Jan 18, 2019 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XM... |
| CVE-2019-3772 | — | — | 3.0% | Jan 18, 2019 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now