2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6257 | HIGH | 7.7 | 1.1% | Jan 14, 2019 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the ... |
| CVE-2019-6256 | — | — | 2.4% | Jan 14, 2019 | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. ... |
| CVE-2019-6251 | — | — | 4.1% | Jan 14, 2019 | WebKitGTK and WPE WebKit prior to version 2.24.1 are vulnerable to address bar spoofing upon certain JavaScript redirect... |
| CVE-2019-6250 | — | — | 9.4% | Jan 13, 2019 | A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_de... |
| CVE-2019-6249 | — | — | 3.0% | Jan 13, 2019 | An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde... |
| CVE-2019-6248 | — | — | 0.7% | Jan 13, 2019 | PHP Scripts Mall Citysearch / Hotfrog / Gelbeseiten Clone Script 2.0.1 has Reflected XSS via the srch parameter, as demo... |
| CVE-2019-6247 | — | — | 2.5% | Jan 13, 2019 | An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. A heap-based buffer overflo... |
| CVE-2019-6246 | — | — | 1.8% | Jan 13, 2019 | An issue was discovered in SVG++ (aka svgpp) 1.2.3. After calling the gil::get_color function in Generic Image Library i... |
| CVE-2019-6245 | HIGH | 8.8 | 2.0% | Jan 13, 2019 | An issue was discovered in Anti-Grain Geometry (AGG) 2.4 as used in SVG++ (aka svgpp) 1.2.3. In the function agg::cell_a... |
| CVE-2019-6244 | — | — | 0.5% | Jan 12, 2019 | An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL stat... |
| CVE-2019-6243 | — | — | 0.7% | Jan 12, 2019 | Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). |
| CVE-2019-3803 | MEDIUM | 4.5 | 0.6% | Jan 12, 2019 | Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote atta... |
| CVE-2019-6138 | — | — | 1.5% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory le... |
| CVE-2019-6137 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereferenc... |
| CVE-2019-6136 | — | — | 1.5% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a S... |
| CVE-2019-6135 | — | — | 1.7% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called fr... |
| CVE-2019-6133 | — | — | 0.4% | Jan 11, 2019 | In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and... |
| CVE-2019-6132 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStrea... |
| CVE-2019-6131 | — | — | 1.5% | Jan 11, 2019 | svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, ... |
| CVE-2019-6130 | — | — | 1.6% | Jan 11, 2019 | Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. Thi... |
| CVE-2019-6129 | MEDIUM | 6.5 | 1.4% | Jan 11, 2019 | png_create_info_struct in png.c in libpng 1.6.36 has a memory leak, as demonstrated by pngcp. NOTE: a third party has st... |
| CVE-2019-6128 | HIGH | 8.8 | 3.9% | Jan 11, 2019 | The TIFFFdOpen function in tif_unix.c in LibTIFF 4.0.10 has a memory leak, as demonstrated by pal2rgb. |
| CVE-2019-6127 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be use... |
| CVE-2019-6126 | — | — | 1.4% | Jan 11, 2019 | The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended ac... |
| CVE-2019-0088 | — | — | 0.3% | Jan 10, 2019 | Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated use... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now