2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19376 | MEDIUM | 6.5 | 1.0% | Nov 28, 2019 | In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API reque... |
| CVE-2019-19375 | MEDIUM | 5.3 | 0.4% | Nov 28, 2019 | In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes se... |
| CVE-2019-19318 | MEDIUM | 4.4 | 0.6% | Nov 28, 2019 | In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free b... |
| CVE-2019-19319 | MEDIUM | 6.5 | 0.7% | Nov 27, 2019 | In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bou... |
| CVE-2019-18660 | MEDIUM | 4.7 | 0.7% | Nov 27, 2019 | The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place ... |
| CVE-2019-6670 | MEDIUM | 4.4 | 0.2% | Nov 27, 2019 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hyperviso... |
| CVE-2019-6668 | MEDIUM | 5.5 | 0.3% | Nov 27, 2019 | The BIG-IP APM Edge Client for macOS bundled with BIG-IP APM 15.0.0-15.0.1, 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.1.0-13.... |
| CVE-2019-19367 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/fax/fax_files.php in FusionPBX 4.4.1 allows remote attackers to inject... |
| CVE-2019-19366 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | A cross-site scripting (XSS) vulnerability in app/xml_cdr/xml_cdr_search.php in FusionPBX 4.4.1 allows remote attackers ... |
| CVE-2019-19242 | MEDIUM | 5.9 | 2.5% | Nov 27, 2019 | SQLite 3.30.1 mishandles pExpr->y.pTab, as demonstrated by the TK_COLUMN case in sqlite3ExprCodeTarget in expr.c. |
| CVE-2019-19329 | MEDIUM | 6.1 | 1.4% | Nov 27, 2019 | In Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07, when mathematical expressions in results are di... |
| CVE-2019-19328 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | ui/editor/tooltip/Rdf.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection i... |
| CVE-2019-19327 | MEDIUM | 6.1 | 0.9% | Nov 27, 2019 | ui/ResultView.js in Wikibase Wikidata Query Service GUI before 0.3.6-SNAPSHOT 2019-11-07 allows HTML injection when repo... |
| CVE-2019-19308 | MEDIUM | 5.5 | 0.9% | Nov 27, 2019 | In text_to_glyphs in sushi-font-widget.c in gnome-font-viewer 3.34.0, there is a NULL pointer dereference while parsing ... |
| CVE-2019-13936 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-13935 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-13934 | MEDIUM | 5.4 | 0.5% | Nov 27, 2019 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webclient of Sieme... |
| CVE-2019-10195 | MEDIUM | 6.5 | 1.4% | Nov 27, 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ... |
| CVE-2019-16388 | MEDIUM | 4.3 | 0.7% | Nov 26, 2019 | PEGA Platform 8.3.0 is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyStream=MyAle... |
| CVE-2019-16386 | MEDIUM | 4.3 | 0.8% | Nov 26, 2019 | PEGA Platform 7.x and 8.x is vulnerable to Information disclosure via a direct prweb/sso/random_token/!STANDARD?pyActivi... |
| CVE-2019-16254 | MEDIUM | 5.3 | 4.6% | Nov 26, 2019 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBr... |
| CVE-2019-16195 | MEDIUM | 6.1 | 1.3% | Nov 26, 2019 | Centreon before 2.8.30, 18.x before 18.10.8, and 19.x before 19.04.5 allows XSS via myAccount alias and name fields. |
| CVE-2019-18678 | MEDIUM | 5.3 | 10.9% | Nov 26, 2019 | An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend ... |
| CVE-2019-18677 | MEDIUM | 6.1 | 7.2% | Nov 26, 2019 | An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended ch... |
| CVE-2019-18456 | MEDIUM | 5.3 | 0.9% | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by E... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now