2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5893 | — | — | 24.7% | Jan 10, 2019 | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. |
| CVE-2019-5892 | — | — | 2.7% | Jan 10, 2019 | bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x bef... |
| CVE-2019-5887 | — | — | 1.5% | Jan 10, 2019 | An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not ... |
| CVE-2019-5886 | — | — | 1.0% | Jan 10, 2019 | An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lo... |
| CVE-2019-5884 | MEDIUM | 5.9 | 1.3% | Jan 10, 2019 | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or o... |
| CVE-2019-5882 | — | — | 2.5% | Jan 9, 2019 | Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. |
| CVE-2019-3498 | — | — | 3.7% | Jan 9, 2019 | In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elem... |
| CVE-2019-5748 | — | — | 1.7% | Jan 9, 2019 | In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks. |
| CVE-2019-5747 | HIGH | 7.5 | 4.7% | Jan 9, 2019 | An issue was discovered in BusyBox through 1.30.0. An out of bounds read in udhcp components (consumed by the DHCP clien... |
| CVE-2019-0542 | HIGH | 8.8 | 3.2% | Jan 9, 2019 | A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Re... |
| CVE-2019-3581 | HIGH | 7.5 | 2.3% | Jan 9, 2019 | Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to caus... |
| CVE-2019-5725 | — | — | 1.5% | Jan 8, 2019 | qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstr... |
| CVE-2019-5721 | — | — | 0.9% | Jan 8, 2019 | In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by cha... |
| CVE-2019-5719 | — | — | 0.8% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors... |
| CVE-2019-5718 | — | — | 1.4% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was add... |
| CVE-2019-5717 | — | — | 1.4% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/... |
| CVE-2019-5716 | — | — | 1.4% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c b... |
| CVE-2019-0622 | — | — | 2.0% | Jan 8, 2019 | An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication r... |
| CVE-2019-0588 | MEDIUM | 6.5 | 4.6% | Jan 8, 2019 | An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors m... |
| CVE-2019-0586 | CRITICAL | 9.8 | 15.4% | Jan 8, 2019 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o... |
| CVE-2019-0585 | — | — | 22.0% | Jan 8, 2019 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memo... |
| CVE-2019-0584 | — | — | 13.6% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0583 | — | — | 16.1% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0582 | HIGH | 7.8 | 12.3% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
| CVE-2019-0581 | — | — | 13.6% | Jan 8, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now