CVEs from 2019

3,163 normalized CVEs published or assigned in this year.

Total
3,163
critical
critical 238
high
high 485
medium
medium 485
low
low 94
% Critical
7.5%
% with KEV
3.7%
% with exploit
8.0%

Top products

  • u-boot 20
  • crimson 8
  • active_iq_unified_manager 7
  • weblogic_server 5
  • jdk 5
  • oncommand_workflow_automation 5
  • codeready_linux_builder_eus 4
  • oncommand_insight 4
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-6454 medium 5.5 7y ago An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming …
CVE-2019-11324 medium 5.5 7y ago RHSA-2020:1916: python-pip security update (Moderate)
CVE-2019-7164 medium 5.5 7y ago RHSA-2019:0984: python36:3.6 security update (Moderate)
CVE-2019-7548 medium 5.5 7y ago RHSA-2019:0984: python36:3.6 security update (Moderate)
CVE-2019-8321 medium 5.5 7y ago RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
CVE-2019-8322 medium 5.5 7y ago RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
CVE-2019-8323 medium 5.5 7y ago RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
CVE-2019-8325 medium 5.5 7y ago RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
CVE-2019-8320 medium 5.5 7y ago RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
CVE-2019-8331 medium 5.5 7y ago Bootstrap Vulnerable to Cross-Site Scripting
CVE-2019-6975 medium 5.5 7y ago Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a malicious attacker-supplied value to the django.utils.numberformat.format() func…
CVE-2019-3498 medium 5.5 8y ago In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elements in Output Used by a Downstream Component issue exists in django.views.defa…
CVE-2019-3881 medium 5.5 8y ago RHSA-2021:2588: ruby:2.6 security, bug fix, and enhancement update (Moderate)
CVE-2019-13118 medium 5.3 5.3 4y ago In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, …
CVE-2019-13117 medium 5.3 5.3 7y ago In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o…
CVE-2019-16910 medium 5.3 5.3 7y ago Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private…
CVE-2019-7317 medium 5.3 5.3 7y ago png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2019-16230 medium 4.7 4.7 7y ago drivers/gpu/drm/radeon/radeon_display.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. NOTE: A third-party software maintainer stat…
CVE-2019-14360 medium 4.6 4.6 7y ago On Hyundai Pay Kasse HK-1000 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allow…
CVE-2019-15213 medium 4.6 4.6 7y ago An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver.
CVE-2019-25717 medium 4.3 4.3 4d ago Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection…
CVE-2019-25734 medium 4.0 4.0 2d ago Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanit…
CVE-2019-25723 medium 4.0 4.0 4d ago Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by sending specifically crafted n…