2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-19588 | HIGH | 7.5 | 1.2% | Dec 5, 2019 | The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a ... |
| CVE-2019-19553 | HIGH | 7.5 | 4.1% | Dec 5, 2019 | In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/as... |
| CVE-2019-19522 | HIGH | 7.8 | 0.5% | Dec 5, 2019 | OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to beco... |
| CVE-2019-19520 | HIGH | 7.8 | 1.4% | Dec 5, 2019 | xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir... |
| CVE-2019-19519 | HIGH | 7.8 | 0.4% | Dec 5, 2019 | In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is ... |
| CVE-2019-16753 | HIGH | 7.5 | 0.7% | Dec 4, 2019 | An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is... |
| CVE-2019-19364 | HIGH | 7.8 | 0.5% | Dec 4, 2019 | A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and Cata... |
| CVE-2019-18346 | HIGH | 8.8 | 1.0% | Dec 4, 2019 | A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, th... |
| CVE-2019-17555 | HIGH | 7.5 | 2.1% | Dec 4, 2019 | The AsyncResponseWrapperImpl class in Apache Olingo versions 4.0.0 to 4.6.0 reads the Retry-After header and passes it t... |
| CVE-2019-7201 | HIGH | 7.8 | 0.3% | Dec 4, 2019 | An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vul... |
| CVE-2019-11937 | HIGH | 7.5 | 1.4% | Dec 4, 2019 | In Mcrouter prior to v0.41.0, a large struct input provided to the Carbon protocol reader could result in stack exhausti... |
| CVE-2019-11923 | HIGH | 7.5 | 1.5% | Dec 4, 2019 | In Mcrouter prior to v0.41.0, the deprecated ASCII parser would allocate a buffer to a user-specified length with no max... |
| CVE-2019-15638 | HIGH | 7.8 | 0.3% | Dec 4, 2019 | COPA-DATA zenone32 zenon Editor through 8.10 has an Uncontrolled Search Path Element. |
| CVE-2019-14909 | HIGH | 8.3 | 1.1% | Dec 4, 2019 | A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any pa... |
| CVE-2019-18850 | HIGH | 7.5 | 1.2% | Dec 4, 2019 | TrevorC2 v1.1/v1.2 fails to prevent fingerprinting primarily via a discrepancy between response headers when responding ... |
| CVE-2019-5164 | HIGH | 7.8 | 0.7% | Dec 3, 2019 | An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafte... |
| CVE-2019-5163 | HIGH | 7.5 | 2.3% | Dec 3, 2019 | An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When uti... |
| CVE-2019-5133 | HIGH | 8.8 | 3.2% | Dec 3, 2019 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library.... |
| CVE-2019-5132 | HIGH | 8.8 | 3.7% | Dec 3, 2019 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear... |
| CVE-2019-5112 | HIGH | 8.8 | 1.6% | Dec 3, 2019 | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.... |
| CVE-2019-5111 | HIGH | 8.8 | 1.4% | Dec 3, 2019 | Exploitable SQL injection vulnerability exists in the authenticated portion of Forma LMS 2.2.1. The /appLms/ajax.server.... |
| CVE-2019-5110 | HIGH | 8.8 | 1.1% | Dec 3, 2019 | Exploitable SQL injection vulnerabilities exist in the authenticated portion of Forma LMS 2.2.1. Specially crafted web r... |
| CVE-2019-5109 | HIGH | 8.8 | 1.1% | Dec 3, 2019 | Exploitable SQL injection vulnerabilities exists in the authenticated portion of Forma LMS 2.2.1. Specially crafted web ... |
| CVE-2019-5097 | HIGH | 7.5 | 45.1% | Dec 3, 2019 | A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web serv... |
| CVE-2019-5083 | HIGH | 8.8 | 3.6% | Dec 3, 2019 | An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft I... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now