2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14860 | MEDIUM | 6.5 | 1.2% | Nov 8, 2019 | It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker... |
| CVE-2019-14824 | MEDIUM | 6.5 | 1.3% | Nov 8, 2019 | A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute va... |
| CVE-2019-10219 | MEDIUM | 6.1 | 2.2% | Nov 8, 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads ... |
| CVE-2019-15005 | MEDIUM | 4.3 | 1.3% | Nov 8, 2019 | The Atlassian Troubleshooting and Support Tools plugin prior to version 1.17.2 allows an unprivileged user to initiate p... |
| CVE-2019-18821 | MEDIUM | 5.5 | 0.3% | Nov 7, 2019 | Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiCustomPathLib!ExiCustomPathLib::CGradientColorsProfi... |
| CVE-2019-18820 | MEDIUM | 5.5 | 0.4% | Nov 7, 2019 | Eximious Logo Designer 3.82 has Heap Corruption starting at ntdll!RtlpNtMakeTemporaryKey+0x0000000000001a78. |
| CVE-2019-18819 | MEDIUM | 5.5 | 0.4% | Nov 7, 2019 | Eximious Logo Designer 3.82 has a User Mode Write AV starting at ExiVectorRender!StrokeText_Blend+0x00000000000003a7. |
| CVE-2019-3422 | MEDIUM | 6.2 | 1.0% | Nov 7, 2019 | The Sec Consult Security Lab reported an information disclosure vulnerability in MF910S product to ZTE PSIRT in October ... |
| CVE-2019-3764 | MEDIUM | 4.3 | 0.9% | Nov 7, 2019 | Dell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.3... |
| CVE-2019-18816 | MEDIUM | 6.1 | 0.8% | Nov 7, 2019 | po-admin/route.php?mod=post&act=edit in PopojiCMS 2.0.1 allows post[1][content]= stored XSS. |
| CVE-2019-18815 | MEDIUM | 6.1 | 0.7% | Nov 7, 2019 | PopojiCMS 2.0.1 allows refer= Open Redirection. |
| CVE-2019-18811 | MEDIUM | 5.5 | 0.4% | Nov 7, 2019 | A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 all... |
| CVE-2019-18809 | MEDIUM | 4.6 | 0.5% | Nov 7, 2019 | A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through ... |
| CVE-2019-18808 | MEDIUM | 5.5 | 0.3% | Nov 7, 2019 | A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows... |
| CVE-2019-18806 | MEDIUM | 5.5 | 0.3% | Nov 7, 2019 | A memory leak in the ql_alloc_large_buffers() function in drivers/net/ethernet/qlogic/qla3xxx.c in the Linux kernel befo... |
| CVE-2019-17604 | MEDIUM | 4.3 | 0.6% | Nov 7, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to c... |
| CVE-2019-17222 | MEDIUM | 6.1 | 0.7% | Nov 7, 2019 | An issue was discovered on Intelbras WRN 150 1.0.17 devices. There is stored XSS in the Service Name tab of the WAN conf... |
| CVE-2019-16878 | MEDIUM | 5.4 | 0.5% | Nov 7, 2019 | Portainer before 1.22.1 has XSS (issue 2 of 2). |
| CVE-2019-6337 | MEDIUM | 5.2 | 0.4% | Nov 7, 2019 | For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain... |
| CVE-2019-16874 | MEDIUM | 6.5 | 0.9% | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 2 of 4). |
| CVE-2019-16873 | MEDIUM | 5.4 | 0.5% | Nov 7, 2019 | Portainer before 1.22.1 has XSS (issue 1 of 2). |
| CVE-2019-15003 | MEDIUM | 5.3 | 1.7% | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ... |
| CVE-2019-16401 | MEDIUM | 6.5 | 0.5% | Nov 6, 2019 | Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon ... |
| CVE-2019-16400 | MEDIUM | 6.5 | 0.5% | Nov 6, 2019 | Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon ... |
| CVE-2019-12406 | MEDIUM | 6.5 | 6.3% | Nov 6, 2019 | Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now