2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13675 | MEDIUM | 4.3 | 0.7% | Nov 25, 2019 | Insufficient data validation in extensions in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to disable e... |
| CVE-2019-13674 | MEDIUM | 4.3 | 0.7% | Nov 25, 2019 | IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via ... |
| CVE-2019-13671 | MEDIUM | 4.3 | 0.6% | Nov 25, 2019 | UI spoofing in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof security UI via a crafted... |
| CVE-2019-13670 | MEDIUM | 6.5 | 0.9% | Nov 25, 2019 | Insufficient data validation in JavaScript in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potential... |
| CVE-2019-13669 | MEDIUM | 4.3 | 0.7% | Nov 25, 2019 | Incorrect data validation in navigation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof the co... |
| CVE-2019-13667 | MEDIUM | 4.3 | 0.7% | Nov 25, 2019 | Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof... |
| CVE-2019-13665 | MEDIUM | 6.5 | 0.7% | Nov 25, 2019 | Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file... |
| CVE-2019-13664 | MEDIUM | 6.5 | 0.5% | Nov 25, 2019 | Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass cont... |
| CVE-2019-13663 | MEDIUM | 4.3 | 0.6% | Nov 25, 2019 | IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via ... |
| CVE-2019-13662 | MEDIUM | 6.5 | 0.7% | Nov 25, 2019 | Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypas... |
| CVE-2019-13661 | MEDIUM | 4.3 | 0.7% | Nov 25, 2019 | UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a cr... |
| CVE-2019-13660 | MEDIUM | 5.3 | 0.8% | Nov 25, 2019 | UI spoofing in Chromium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to spoof notifications via a cr... |
| CVE-2019-13659 | MEDIUM | 4.3 | 0.6% | Nov 25, 2019 | IDN spoofing in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to perform domain spoofing via ... |
| CVE-2019-10213 | MEDIUM | 6.5 | 1.0% | Nov 25, 2019 | OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level... |
| CVE-2019-10207 | MEDIUM | 5.5 | 0.9% | Nov 25, 2019 | A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and ker... |
| CVE-2019-14891 | MEDIUM | 5 | 0.7% | Nov 25, 2019 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can res... |
| CVE-2019-10214 | MEDIUM | 5.9 | 1.6% | Nov 25, 2019 | The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version... |
| CVE-2019-11291 | MEDIUM | 4.8 | 0.8% | Nov 22, 2019 | Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions p... |
| CVE-2019-18910 | MEDIUM | 6.8 | 0.8% | Nov 22, 2019 | The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker t... |
| CVE-2019-16287 | MEDIUM | 6.8 | 0.7% | Nov 22, 2019 | In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerabi... |
| CVE-2019-16286 | MEDIUM | 6.8 | 0.8% | Nov 22, 2019 | An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by chang... |
| CVE-2019-16285 | MEDIUM | 4.6 | 1.0% | Nov 22, 2019 | If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extra... |
| CVE-2019-15593 | MEDIUM | 6.5 | 1.5% | Nov 22, 2019 | GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a D... |
| CVE-2019-19240 | MEDIUM | 5.3 | 1.5% | Nov 22, 2019 | Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us... |
| CVE-2019-16763 | MEDIUM | 6.1 | 0.7% | Nov 22, 2019 | In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now