2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14541 | — | — | 1.0% | Aug 2, 2019 | GnuCOBOL 2.2 has a stack-based buffer overflow in cb_encode_program_id in cobc/typeck.c via crafted COBOL source code. |
| CVE-2019-10094 | — | — | 2.5% | Aug 2, 2019 | A carefully crafted package/compressed file that, when unzipped/uncompressed yields the same file (a quine), causes a St... |
| CVE-2019-10093 | — | — | 3.7% | Aug 2, 2019 | In Apache Tika 1.19 to 1.21, a carefully crafted 2003ml or 2006ml file could consume all available SAXParsers in the poo... |
| CVE-2019-10088 | — | — | 4.8% | Aug 2, 2019 | A carefully crafted or corrupt zip file can cause an OOM in Apache Tika's RecursiveParserWrapper in versions 1.7-1.21. U... |
| CVE-2019-5501 | — | — | 2.0% | Aug 2, 2019 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthentica... |
| CVE-2019-5493 | — | — | 1.4% | Aug 2, 2019 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information ... |
| CVE-2019-14531 | — | — | 1.8% | Aug 2, 2019 | An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an out of bounds read on iso9660 while parsing System Us... |
| CVE-2019-14235 | — | — | 3.1% | Aug 2, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. If passed certain ... |
| CVE-2019-14233 | — | — | 3.2% | Aug 2, 2019 | An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to the behavio... |
| CVE-2019-14528 | — | — | 1.0% | Aug 2, 2019 | GnuCOBOL 2.2 has a heap-based buffer overflow in read_literal in cobc/scanner.l via crafted COBOL source code. |
| CVE-2019-14517 | — | — | 0.9% | Aug 1, 2019 | pandao Editor.md 1.5.0 allows XSS via the Javascript: string. |
| CVE-2019-5401 | — | — | 0.5% | Aug 1, 2019 | A potential security vulnerability has been identified in HP2910al-48G version W.15.14.0016. The attack exploits an xss ... |
| CVE-2019-14260 | — | — | 2.8% | Aug 1, 2019 | On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injectio... |
| CVE-2019-14491 | — | — | 2.6% | Aug 1, 2019 | An issue was discovered in OpenCV before 3.4.7 and 4.x before 4.1.1. There is an out of bounds read in the function cv::... |
| CVE-2019-14486 | — | — | 1.0% | Aug 1, 2019 | GnuCOBOL 2.2 has a buffer overflow in cb_evaluate_expr in cobc/field.c via crafted COBOL source code. |
| CVE-2019-14472 | — | — | 0.8% | Aug 1, 2019 | Zurmo 3.2.7-2 has XSS via the app/index.php/zurmo/default PATH_INFO. |
| CVE-2019-14471 | — | — | 0.9% | Aug 1, 2019 | TestLink 1.9.19 has XSS via the error.php message parameter. |
| CVE-2019-14259 | — | — | 2.8% | Aug 1, 2019 | On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in t... |
| CVE-2019-14468 | — | — | 1.0% | Aug 1, 2019 | GnuCOBOL 2.2 has a buffer overflow in cb_push_op in cobc/field.c via crafted COBOL source code. |
| CVE-2019-14456 | — | — | 0.6% | Jul 31, 2019 | Opengear console server firmware releases prior to 4.5.0 have a stored XSS vulnerability related to serial port logging.... |
| CVE-2019-3960 | — | — | 3.0% | Jul 31, 2019 | Unrestricted upload of file with dangerous type in WallacePOS 1.4.3 allows a remote, authenticated attacker to execute a... |
| CVE-2019-3959 | — | — | 0.8% | Jul 31, 2019 | Cross-site request forgery in WallacePOS 1.4.3 allows a remote attacker to perform sensitive application actions by tric... |
| CVE-2019-3958 | — | — | 0.9% | Jul 31, 2019 | Insufficient output sanitization in WallacePOS 1.4.3 allows a remote, authenticated attacker to conduct persistent cross... |
| CVE-2019-12750 | — | — | 1.3% | Jul 31, 2019 | Symantec Endpoint Protection, prior to 14.2 RU1 & 12.1 RU6 MP10 and Symantec Endpoint Protection Small Business Edition,... |
| CVE-2019-13568 | — | — | 1.7% | Jul 31, 2019 | CImg through 2.6.7 has a heap-based buffer overflow in _load_bmp in CImg.h because of erroneous memory allocation for a ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now