2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17327 | HIGH | 7.2 | 2.7% | Nov 8, 2019 | JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input paramete... |
| CVE-2019-16209 | HIGH | 7.4 | 0.7% | Nov 8, 2019 | A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to per... |
| CVE-2019-16208 | HIGH | 7.5 | 0.4% | Nov 8, 2019 | Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptogr... |
| CVE-2019-16207 | HIGH | 7.8 | 0.3% | Nov 8, 2019 | Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access... |
| CVE-2019-16205 | HIGH | 8.8 | 1.3% | Nov 8, 2019 | A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID.... |
| CVE-2019-10222 | HIGH | 7.5 | 4.6% | Nov 8, 2019 | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated ... |
| CVE-2019-3465 | HIGH | 8.8 | 3.0% | Nov 7, 2019 | Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validat... |
| CVE-2019-18813 | HIGH | 7.5 | 3.9% | Nov 7, 2019 | A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows a... |
| CVE-2019-18812 | HIGH | 7.5 | 3.3% | Nov 7, 2019 | A memory leak in the sof_dfsentry_write() function in sound/soc/sof/debug.c in the Linux kernel through 5.3.9 allows att... |
| CVE-2019-18810 | HIGH | 7.5 | 3.3% | Nov 7, 2019 | A memory leak in the komeda_wb_connector_add() function in drivers/gpu/drm/arm/display/komeda/komeda_wb_connector.c in t... |
| CVE-2019-18807 | HIGH | 7.5 | 2.6% | Nov 7, 2019 | Two memory leaks in the sja1105_static_config_upload() function in drivers/net/dsa/sja1105/sja1105_spi.c in the Linux ke... |
| CVE-2019-17605 | HIGH | 8.8 | 1.1% | Nov 7, 2019 | A mass assignment vulnerability in eyecomms eyeCMS through 2019-10-15 allows any candidate to take over another candidat... |
| CVE-2019-16877 | HIGH | 8.8 | 1.0% | Nov 7, 2019 | Portainer before 1.22.1 has Incorrect Access Control (issue 4 of 4). |
| CVE-2019-16876 | HIGH | 7.5 | 1.4% | Nov 7, 2019 | Portainer before 1.22.1 allows Directory Traversal. |
| CVE-2019-12331 | HIGH | 8.8 | 1.4% | Nov 7, 2019 | PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if ... |
| CVE-2019-18804 | HIGH | 7.5 | 3.7% | Nov 7, 2019 | DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. |
| CVE-2019-15004 | HIGH | 7.5 | 3.9% | Nov 7, 2019 | The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from ... |
| CVE-2019-18411 | HIGH | 8.8 | 2.3% | Nov 6, 2019 | Zoho ManageEngine ADSelfService Plus 5.x through 5803 has CSRF on the users' profile information page. Users who are att... |
| CVE-2019-5125 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20. A specially cra... |
| CVE-2019-5100 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable integer overflow vulnerability exists in the BMP header parsing functionality of LEADTOOLS 20. A speciall... |
| CVE-2019-5099 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable integer underflow vulnerability exists in the CMP-parsing functionality of LEADTOOLS 20. A specially craf... |
| CVE-2019-5084 | HIGH | 7.8 | 2.0% | Nov 6, 2019 | An exploitable heap out-of-bounds write vulnerability exists in the TIF-parsing functionality of LEADTOOLS 20. A special... |
| CVE-2019-6120 | HIGH | 7.5 | 1.7% | Nov 6, 2019 | An issue was discovered in NiceHash Miner before 2.0.3.0. A missing rate limit while adding a wallet via Email address a... |
| CVE-2019-2246 | HIGH | 7.8 | 0.2% | Nov 6, 2019 | Thread start can cause invalid memory writes to arbitrary memory location since the argument is passed by user to kernel... |
| CVE-2019-10529 | HIGH | 8.1 | 1.7% | Nov 6, 2019 | Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now