CVEs from 2019

3,162 normalized CVEs published or assigned in this year.

Total
3,162
critical
critical 238
high
high 484
medium
medium 485
low
low 95
% Critical
7.5%
% with KEV
3.7%
% with exploit
8.0%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-0213 unknown 7y ago Cross-site scripting in Apache Archiva
CVE-2019-0214 unknown 7y ago Improper Input Validation in Apache Archiva
CVE-2019-0194 unknown 7y ago Path Traversal in Apache Camel
CVE-2019-3868 unknown 7y ago Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
CVE-2019-15542 unknown 7y ago An issue was discovered in the ammonia crate before 2.1.0 for Rust. There is uncontrolled recursion during HTML DOM tree serialization.
CVE-2019-10246 unknown 7y ago Information Exposure vulnerability in Eclipse Jetty
CVE-2019-10247 unknown 7y ago Installation information leak in Eclipse Jetty
CVE-2019-10241 unknown 7y ago Cross-site Scripting in Eclipse Jetty
CVE-2019-5427 unknown 7y ago Billion laughs attack in c3p0
CVE-2019-11404 unknown 7y ago Missing Encryption of Sensitive Data in arrow-kt Arrow
CVE-2019-10686 unknown 7y ago Server-Side Request Forgery (SSRF) in com.ctrip.framework.apollo:apollo
CVE-2019-3795 unknown 7y ago Spring Security uses insufficiently random values
CVE-2019-10240 unknown 7y ago Cleartext Transmission of Sensitive Information, Inclusion of Functionality from Untrusted Control Sphere , and Download of Code Without Integrity Check in Eclipse hawkBit
CVE-2019-0225 unknown 7y ago Improper Limitation of a Pathname ('Path Traversal') in org.apache.jspwiki:jspwiki-war
CVE-2019-1010260 unknown 7y ago High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-core
CVE-2019-0212 unknown 7y ago Improper Authorization in org.apache.hbase:hbase
CVE-2019-0224 unknown 7y ago Moderate severity vulnerability that affects org.apache.jspwiki:jspwiki-main
CVE-2019-0222 unknown 7y ago Improper Control of Generation of Code ('Code Injection') in org.apache.activemq:activemq-client
CVE-2019-10648 unknown 7y ago Robocode vulnerabilities
CVE-2019-0191 unknown 7y ago Moderate severity vulnerability that affects org.apache.karaf:apache-karaf and org.apache.karaf:karaf
CVE-2019-0192 unknown 7y ago Critical severity vulnerability that affects org.apache.solr:solr-core
CVE-2019-9658 unknown 7y ago Moderate severity vulnerability that affects com.puppycrawl.tools:checkstyle
CVE-2019-0200 unknown 7y ago Improper Input Validation in Apache Qpid Broker-J
CVE-2019-0187 unknown 7y ago Unauthenticated Remote Code Execution in Apache JMeter
CVE-2019-9212 unknown 7y ago Incomplete List of Disallowed Inputs in SOFA-Hessian
CVE-2019-9142 unknown 7y ago Moderate severity vulnerability that affects org.b3log:symphony
CVE-2019-3774 unknown 8y ago Low severity vulnerability that affects org.springframework.batch:spring-batch-core
CVE-2019-3773 unknown 8y ago Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
CVE-2019-3772 unknown 8y ago Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml