2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14289 | — | — | 1.0% | Jul 27, 2019 | An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Strea... |
| CVE-2019-14288 | — | — | 1.0% | Jul 27, 2019 | An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Strea... |
| CVE-2019-14286 | — | — | 0.8% | Jul 27, 2019 | In app/webroot/js/event-graph.js in MISP 2.4.111, a stored XSS vulnerability exists in the event-graph view when a user ... |
| CVE-2019-13588 | — | — | 1.0% | Jul 26, 2019 | A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows r... |
| CVE-2019-10267 | — | — | 75.8% | Jul 26, 2019 | An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to ... |
| CVE-2019-10266 | — | — | 13.3% | Jul 26, 2019 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL... |
| CVE-2019-10265 | — | — | 2.5% | Jul 26, 2019 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. On the /cbs/system/ShowAdvanced.do "File Explorer" ... |
| CVE-2019-10264 | — | — | 1.3% | Jul 26, 2019 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Imp... |
| CVE-2019-10263 | — | — | 0.8% | Jul 26, 2019 | An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When creating a trial account, it is possible to in... |
| CVE-2019-1000033 | — | — | — | Jul 26, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-1010259. Reason: This candidate is a reservation... |
| CVE-2019-9492 | — | — | 0.6% | Jul 26, 2019 | A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain... |
| CVE-2019-14284 | — | — | 0.7% | Jul 26, 2019 | In the Linux kernel before 5.2.3, drivers/block/floppy.c allows a denial of service by setup_format_params division-by-z... |
| CVE-2019-14283 | — | — | 0.7% | Jul 26, 2019 | In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as ... |
| CVE-2019-14228 | — | — | 0.4% | Jul 26, 2019 | Xavier PHP Management Panel 3.0 is vulnerable to Reflected POST-based XSS via the username parameter when registering a ... |
| CVE-2019-13955 | — | — | 3.8% | Jul 26, 2019 | Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP re... |
| CVE-2019-13954 | — | — | 4.3% | Jul 26, 2019 | Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP r... |
| CVE-2019-13638 | — | — | 4.5% | Jul 26, 2019 | GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch fil... |
| CVE-2019-13382 | — | — | 1.6% | Jul 26, 2019 | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA... |
| CVE-2019-14282 | — | — | 3.1% | Jul 26, 2019 | The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a... |
| CVE-2019-14281 | — | — | 3.1% | Jul 26, 2019 | The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third ... |
| CVE-2019-14280 | — | — | 8.0% | Jul 26, 2019 | In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe... |
| CVE-2019-10976 | — | — | 1.0% | Jul 26, 2019 | Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the ... |
| CVE-2019-1010147 | — | — | 0.7% | Jul 26, 2019 | Yellowfin Smart Reporting All Versions Prior to 7.3 is affected by: Incorrect Access Control - Privileges Escalation. Th... |
| CVE-2019-0202 | — | — | 2.0% | Jul 26, 2019 | The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In ... |
| CVE-2019-11922 | — | — | 1.4% | Jul 25, 2019 | A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to wr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now