CVEs from 2019
Total
3,311
critical
critical 232
high
high 336
medium
medium 309
low
low 71
% Critical
7.0%
% with KEV
3.6%
% with exploit
4.3%
Top products
- u-boot 20
- active_iq_unified_manager 7
- jdk 5
- weblogic_server 5
- oncommand_workflow_automation 5
- codeready_linux_builder_eus 4
- oncommand_insight 4
- libxslt 4
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-5868 | high | — | 8.0 | — | arbitrary code execution in chromium | |||
| CVE-2019-6116 | high | — | 8.0 | — | In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution. | |||
| CVE-2019-5855 | high | — | 8.0 | — | multiple issues in chromium | |||
| CVE-2019-11749 | high | — | 8.0 | — | A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggeri… | |||
| CVE-2019-14817 | high | — | 8.0 | — | A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrict… | |||
| CVE-2019-11752 | high | — | 8.0 | — | It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects … | |||
| CVE-2019-2201 | high | — | 8.0 | — | In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged proces… | |||
| CVE-2019-19450 | high | — | 8.0 | 3y ago | Important: python-reportlab security update | |||
| CVE-2019-18466 | high | — | 8.0 | 4y ago | Important: container-tools:rhel8 security and bug fix update | |||
| CVE-2019-9512 | high | — | 8.0 | 4y ago | Important: container-tools:rhel8 security and bug fix update | |||
| CVE-2019-9514 | high | — | 8.0 | 4y ago | Important: nodejs:10 security update | |||
| CVE-2019-10353 | high | — | 8.0 | 4y ago | Cross-Site Request Forgery in Jenkins | |||
| CVE-2019-10352 | high | — | 8.0 | 4y ago | Improper Limitation of a Pathname to a Restricted Directory in Jenkins | |||
| CVE-2019-10354 | high | — | 8.0 | 4y ago | Missing Authorization in Jenkins | |||
| CVE-2019-16276 | high | — | 8.0 | 4y ago | Request smuggling due to accepting invalid headers in net/http via net/textproto | |||
| CVE-2019-2435 | high | — | 8.0 | 4y ago | Improper Access Control in MySQL Connector Python | |||
| CVE-2019-5885 | high | — | 8.0 | 4y ago | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers … | |||
| CVE-2019-16884 | high | — | 8.0 | 4y ago | Important: container-tools:rhel8 security and bug fix update | |||
| CVE-2019-10214 | high | — | 8.0 | 4y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |||
| CVE-2019-18811 | high | — | 8.0 | 5y ago | A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering s… | |||
| CVE-2019-19528 | high | — | 8.0 | 5y ago | In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver, aka CID-edc4746f253d. | |||
| CVE-2019-19523 | high | — | 8.0 | 5y ago | In the Linux kernel before 5.3.7, there is a use-after-free bug that can be caused by a malicious USB device in the drivers/usb/misc/adutux.c driver, aka CID-44efc269db79. | |||
| CVE-2019-2938 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2974 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-15890 | high | — | 8.0 | 6y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |||
| CVE-2019-2914 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2960 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2967 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2966 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2968 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-3009 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-3011 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-3018 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2911 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2957 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2982 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-3004 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2946 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2991 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2993 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2997 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2963 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2998 | high | — | 8.0 | 6y ago | Important: mysql:8.0 security update | |||
| CVE-2019-20382 | high | — | 8.0 | 6y ago | Important: virt:rhel security update | |||
| CVE-2019-10086 | high | — | 8.0 | 6y ago | Insecure Deserialization in Apache Commons Beanutils | |||
| CVE-2019-0199 | high | — | 8.0 | 6y ago | Apache Tomcat Denial of Service vulnerability | |||
| CVE-2019-12525 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |||
| CVE-2019-12519 | high | — | 8.0 | 6y ago | Important: squid:4 security update | |||
| CVE-2019-20044 | high | — | 8.0 | 6y ago | Important: zsh security update | |||
| CVE-2019-15604 | high | — | 8.0 | 6y ago | Important: nodejs:10 security update | |||
| CVE-2019-15605 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |||
| CVE-2019-15606 | high | — | 8.0 | 6y ago | Important: nodejs:12 security update | |||
| CVE-2019-19844 | high | — | 8.0 | 6y ago | Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address (that is equal to an existing user's email address after case transformation of… | |||
| CVE-2019-16777 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-16776 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-16775 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-14378 | high | — | 8.0 | 7y ago | Important: container-tools:1.0 security and bug fix update | |||
| CVE-2019-9946 | high | — | 8.0 | 7y ago | Important: container-tools:rhel8 security, bug fix, and enhancement update | |||
| CVE-2019-2510 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-9518 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-9515 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-9517 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-5737 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-9511 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-9513 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-9516 | high | — | 8.0 | 7y ago | Important: nodejs:10 security update | |||
| CVE-2019-12527 | high | — | 8.0 | 7y ago | Important: squid:4 security update | |||
| CVE-2019-0203 | high | — | 8.0 | 7y ago | Important: subversion:1.10 security update | |||
| CVE-2019-2436 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2738 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2687 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2689 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2685 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2634 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2691 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2948 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-3003 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2606 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2969 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2503 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2585 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2819 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2774 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2617 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2502 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2486 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2495 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2434 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2800 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2630 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2693 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2688 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2686 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2681 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2530 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2620 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2596 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2536 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2778 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update | |||
| CVE-2019-2533 | high | — | 8.0 | 7y ago | Important: mysql:8.0 security update |