2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0010 | HIGH | 7.5 | 2.7% | Jan 15, 2019 | An SRX Series Service Gateway configured for Unified Threat Management (UTM) may experience a system crash with the erro... |
| CVE-2019-0009 | MEDIUM | 5.5 | 0.4% | Jan 15, 2019 | On EX2300 and EX3400 series, high disk I/O operations may disrupt the communication between the routing engine (RE) and ... |
| CVE-2019-0007 | CRITICAL | 9.3 | 1.7% | Jan 15, 2019 | The vMX Series software uses a predictable IP ID Sequence Number. This leaves the system as well as clients connecting t... |
| CVE-2019-0006 | CRITICAL | 9.8 | 5.3% | Jan 15, 2019 | A certain crafted HTTP packet can trigger an uninitialized function pointer deference vulnerability in the Packet Forwar... |
| CVE-2019-0005 | MEDIUM | 5.3 | 1.2% | Jan 15, 2019 | On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any I... |
| CVE-2019-0004 | MEDIUM | 5.5 | 0.3% | Jan 15, 2019 | On Juniper ATP, the API key and the device key are logged in a file readable by authenticated local users. These keys ar... |
| CVE-2019-0003 | MEDIUM | 5.9 | 2.0% | Jan 15, 2019 | When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a speci... |
| CVE-2019-0002 | CRITICAL | 9.8 | 2.4% | Jan 15, 2019 | On EX2300 and EX3400 series, stateless firewall filter configuration that uses the action 'policer' in combination with ... |
| CVE-2019-0001 | HIGH | 7.5 | 3.0% | Jan 15, 2019 | Receipt of a malformed packet on MX Series devices with dynamic vlan configuration can trigger an uncontrolled recursion... |
| CVE-2019-3811 | MEDIUM | 5.2 | 0.7% | Jan 15, 2019 | A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root ... |
| CVE-2019-6296 | — | — | 1.3% | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/export_ajax.php id parameter. |
| CVE-2019-6295 | — | — | 1.3% | Jan 15, 2019 | Cleanto 5.0 has SQL Injection via the assets/lib/service_method_ajax.php service_id parameter. |
| CVE-2019-6294 | — | — | 0.5% | Jan 15, 2019 | An issue was discovered in EasyCMS 1.5. There is CSRF via the index.php?s=/admin/articlem/insert/navTabId/listarticle/ca... |
| CVE-2019-6289 | — | — | 1.9% | Jan 15, 2019 | uploads/include/dialog/select_soft.php in DedeCMS V57_UTF8_SP2 allows remote attackers to execute arbitrary PHP code by ... |
| CVE-2019-6293 | — | — | 1.6% | Jan 15, 2019 | An issue was discovered in the function mark_beginning_as_normal in nfa.c in flex 2.6.4. There is a stack exhaustion pro... |
| CVE-2019-6292 | — | — | 1.7% | Jan 15, 2019 | An issue was discovered in singledocparser.cpp in yaml-cpp (aka LibYaml-C++) 0.6.2. Stack Exhaustion occurs in YAML::Sin... |
| CVE-2019-6291 | — | — | 1.3% | Jan 15, 2019 | An issue was discovered in the function expr6 in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack ex... |
| CVE-2019-6290 | — | — | 1.3% | Jan 15, 2019 | An infinite recursion issue was discovered in eval.c in Netwide Assembler (NASM) through 2.14.02. There is a stack exhau... |
| CVE-2019-6267 | — | — | 1.4% | Jan 15, 2019 | The Premium WP Suite Easy Redirect Manager plugin 28.07-17 for WordPress has XSS via a crafted GET request that is misha... |
| CVE-2019-6286 | — | — | 2.1% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::skip_over_scopes in prelexer.hpp when called f... |
| CVE-2019-6285 | — | — | 2.5% | Jan 14, 2019 | The SingleDocParser::HandleFlowSequence function in yaml-cpp (aka LibYaml-C++) 0.6.2 allows remote attackers to cause a ... |
| CVE-2019-6284 | MEDIUM | 6.5 | 2.1% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::alternatives in prelexer.hpp. |
| CVE-2019-6283 | MEDIUM | 6.5 | 1.9% | Jan 14, 2019 | In LibSass 3.5.5, a heap-based buffer over-read exists in Sass::Prelexer::parenthese_scope in prelexer.hpp. |
| CVE-2019-6278 | — | — | 0.5% | Jan 14, 2019 | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option. |
| CVE-2019-6259 | — | — | 1.5% | Jan 14, 2019 | An issue was discovered in idreamsoft iCMS V7.0.13. There is SQL Injection via the app/article/article.admincp.php _data... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now