2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14812 | HIGH | 7.8 | 2.5% | Nov 27, 2019 | A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly... |
| CVE-2019-10216 | HIGH | 7.8 | 2.3% | Nov 27, 2019 | In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scr... |
| CVE-2019-14867 | HIGH | 8.8 | 6.3% | Nov 27, 2019 | A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before ... |
| CVE-2019-17590 | HIGH | 8.8 | 0.6% | Nov 26, 2019 | The csrf_callback function in the CSRF Magic library through 2016-03-27 is vulnerable to CSRF protection bypass as it al... |
| CVE-2019-16387 | HIGH | 8.1 | 1.0% | Nov 26, 2019 | PEGA Platform 8.3.0 is vulnerable to a direct prweb/sso/random_token/!STANDARD?pyActivity=Data-Admin-DB-Name.DBSchema_Li... |
| CVE-2019-16255 | HIGH | 8.1 | 4.2% | Nov 26, 2019 | Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "c... |
| CVE-2019-16201 | HIGH | 7.5 | 5.1% | Nov 26, 2019 | WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expressi... |
| CVE-2019-18679 | HIGH | 7.5 | 41.0% | Nov 26, 2019 | An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to in... |
| CVE-2019-18676 | HIGH | 7.5 | 9.2% | Nov 26, 2019 | An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffe... |
| CVE-2019-18455 | HIGH | 7.5 | 1.5% | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11 through 12.4 when building Nested GraphQL queries.... |
| CVE-2019-7319 | HIGH | 8.3 | 1.0% | Nov 26, 2019 | An issue was discovered in Cloudera Hue 6.0.0 through 6.1.0. When using one of following authentication backends: LdapBa... |
| CVE-2019-6477 | HIGH | 7.5 | 4.0% | Nov 26, 2019 | With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query receiv... |
| CVE-2019-4387 | HIGH | 8.8 | 1.0% | Nov 26, 2019 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.2.0 is vulnerable to SQL injection. A remote attacker c... |
| CVE-2019-18457 | HIGH | 8.8 | 1.0% | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It ... |
| CVE-2019-19275 | HIGH | 7.5 | 3.3% | Nov 26, 2019 | typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python in... |
| CVE-2019-19274 | HIGH | 7.5 | 3.3% | Nov 26, 2019 | typed_ast 1.3.0 and 1.3.1 has a handle_keywordonly_args out-of-bounds read. An attacker with the ability to cause a Pyth... |
| CVE-2019-18460 | HIGH | 7.5 | 1.2% | Nov 26, 2019 | An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature prov... |
| CVE-2019-14853 | HIGH | 7.5 | 2.5% | Nov 26, 2019 | An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatu... |
| CVE-2019-14890 | HIGH | 8.4 | 0.2% | Nov 26, 2019 | A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames an... |
| CVE-2019-19272 | HIGH | 7.5 | 0.9% | Nov 26, 2019 | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. Direct dereference of a NULL pointer (a variable init... |
| CVE-2019-19271 | HIGH | 7.5 | 1.1% | Nov 26, 2019 | An issue was discovered in tls_verify_crl in ProFTPD before 1.3.6. A wrong iteration variable, used when checking a clie... |
| CVE-2019-19270 | HIGH | 7.5 | 1.0% | Nov 26, 2019 | An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL... |
| CVE-2019-15972 | HIGH | 8.8 | 1.6% | Nov 26, 2019 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticat... |
| CVE-2019-15956 | HIGH | 8.8 | 1.0% | Nov 26, 2019 | A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could a... |
| CVE-2019-15288 | HIGH | 8.8 | 1.7% | Nov 26, 2019 | A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE), Cisco TelePresence Codec (TC), and Cisco R... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now