2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11255 | MEDIUM | 6.5 | 1.7% | Dec 5, 2019 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2... |
| CVE-2019-19602 | MEDIUM | 6.1 | 0.6% | Dec 5, 2019 | fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the Linux kernel before 5.4.2, when GCC 9 is used, allows c... |
| CVE-2019-19596 | MEDIUM | 5.4 | 0.7% | Dec 5, 2019 | GitBook through 2.6.9 allows XSS via a local .md file. |
| CVE-2019-19587 | MEDIUM | 6.1 | 0.6% | Dec 5, 2019 | In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the sou... |
| CVE-2019-19579 | MEDIUM | 6.8 | 0.5% | Dec 4, 2019 | An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where... |
| CVE-2019-16752 | MEDIUM | 4.3 | 0.4% | Dec 4, 2019 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wal... |
| CVE-2019-11216 | MEDIUM | 6.5 | 1.8% | Dec 4, 2019 | BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XM... |
| CVE-2019-19229 | MEDIUM | 6.5 | 2.3% | Dec 4, 2019 | admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= D... |
| CVE-2019-19133 | MEDIUM | 6.1 | 1.9% | Dec 4, 2019 | The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page requ... |
| CVE-2019-18347 | MEDIUM | 5.4 | 1.1% | Dec 4, 2019 | A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields tha... |
| CVE-2019-7197 | MEDIUM | 4.8 | 1.2% | Dec 4, 2019 | A stored cross-site scripting (XSS) vulnerability has been reported to affect multiple versions of QTS. If exploited, th... |
| CVE-2019-19555 | MEDIUM | 5.5 | 1.1% | Dec 4, 2019 | read_textobject in read.c in Xfig fig2dev 3.2.7b has a stack-based buffer overflow because of an incorrect sscanf. |
| CVE-2019-17554 | MEDIUM | 5.5 | 12.2% | Dec 4, 2019 | The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti... |
| CVE-2019-3750 | MEDIUM | 5.5 | 0.3% | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici... |
| CVE-2019-3749 | MEDIUM | 5.5 | 0.3% | Dec 3, 2019 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malici... |
| CVE-2019-18574 | MEDIUM | 4.8 | 0.6% | Dec 3, 2019 | RSA Authentication Manager software versions prior to 8.4 P8 contain a stored cross-site scripting vulnerability in the ... |
| CVE-2019-19457 | MEDIUM | 5.4 | 0.6% | Dec 3, 2019 | SALTO ProAccess SPACE 5.4.3.0 allows XSS. |
| CVE-2019-18993 | MEDIUM | 5.4 | 0.5% | Dec 3, 2019 | OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI... |
| CVE-2019-18992 | MEDIUM | 5.4 | 0.5% | Dec 3, 2019 | OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on ro... |
| CVE-2019-13456 | MEDIUM | 6.5 | 1.6% | Dec 3, 2019 | In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element canno... |
| CVE-2019-19460 | MEDIUM | 5.5 | 0.4% | Dec 3, 2019 | An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local S... |
| CVE-2019-3990 | MEDIUM | 4.3 | 1.0% | Dec 3, 2019 | A User Enumeration flaw exists in Harbor. The issue is present in the "/users" API endpoint. This endpoint is supposed t... |
| CVE-2019-19537 | MEDIUM | 4.2 | 0.3% | Dec 3, 2019 | In the Linux kernel before 5.2.10, there is a race condition bug that can be caused by a malicious USB device in the USB... |
| CVE-2019-19536 | MEDIUM | 4.6 | 0.4% | Dec 3, 2019 | In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/... |
| CVE-2019-19535 | MEDIUM | 4.6 | 0.5% | Dec 3, 2019 | In the Linux kernel before 5.2.9, there is an info-leak bug that can be caused by a malicious USB device in the drivers/... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now