2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18848 | HIGH | 7.5 | 1.3% | Nov 12, 2019 | The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. |
| CVE-2019-18817 | HIGH | 7.5 | 1.2% | Nov 12, 2019 | Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related... |
| CVE-2019-18874 | HIGH | 7.5 | 3.5% | Nov 12, 2019 | psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a wh... |
| CVE-2019-18862 | HIGH | 7.8 | 1.1% | Nov 11, 2019 | maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. |
| CVE-2019-18857 | HIGH | 7.5 | 1.0% | Nov 11, 2019 | darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected w... |
| CVE-2019-18856 | HIGH | 7.5 | 1.4% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to... |
| CVE-2019-18855 | HIGH | 7.5 | 2.6% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to p... |
| CVE-2019-18854 | HIGH | 7.5 | 2.6% | Nov 11, 2019 | A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to u... |
| CVE-2019-18841 | HIGH | 7.3 | 1.4% | Nov 11, 2019 | Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. |
| CVE-2019-18836 | HIGH | 7.5 | 1.9% | Nov 11, 2019 | Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connectio... |
| CVE-2019-18845 | HIGH | 7.1 | 0.4% | Nov 9, 2019 | The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity process... |
| CVE-2019-18840 | HIGH | 7.5 | 2.0% | Nov 9, 2019 | In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data wh... |
| CVE-2019-5701 | HIGH | 7.8 | 0.5% | Nov 9, 2019 | NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in whic... |
| CVE-2019-5697 | HIGH | 7.1 | 0.3% | Nov 9, 2019 | NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which it may grant a guest access to memory that i... |
| CVE-2019-5692 | HIGH | 7.8 | 0.4% | Nov 9, 2019 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle... |
| CVE-2019-5691 | HIGH | 7.8 | 0.4% | Nov 9, 2019 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle... |
| CVE-2019-5690 | HIGH | 7.8 | 0.4% | Nov 9, 2019 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle... |
| CVE-2019-5689 | HIGH | 7.8 | 0.3% | Nov 9, 2019 | NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a... |
| CVE-2019-13543 | HIGH | 7.5 | 1.9% | Nov 8, 2019 | Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4... |
| CVE-2019-13539 | HIGH | 7.8 | 0.3% | Nov 8, 2019 | Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4... |
| CVE-2019-3426 | HIGH | 8.8 | 1.0% | Nov 8, 2019 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vul... |
| CVE-2019-3425 | HIGH | 8.8 | 1.0% | Nov 8, 2019 | The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permiss... |
| CVE-2019-12410 | HIGH | 7.5 | 4.7% | Nov 8, 2019 | While investigating UBSAN errors in https://github.com/apache/arrow/pull/5365 it was discovered Apache Arrow versions 0.... |
| CVE-2019-12408 | HIGH | 7.5 | 3.2% | Nov 8, 2019 | It was discovered that the C++ implementation (which underlies the R, Python and Ruby implementations) of Apache Arrow 0... |
| CVE-2019-17661 | HIGH | 8.8 | 2.4% | Nov 8, 2019 | A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress allows malicious users to ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now