2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9509MEDIUM5.4The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST paramet...
CVE-2019-9508LOW3.5The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authent...
CVE-2019-9507HIGH7.2The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the applica...
CVE-2019-19913MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
CVE-2019-19912MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature a...
CVE-2019-19606CRITICAL9.8X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary...
CVE-2019-19605CRITICAL9.8X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or...
CVE-2019-20634LOW3.7An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email he...
CVE-2019-17561HIGH7.5The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded...
CVE-2019-17560CRITICAL9.1The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This...
CVE-2019-7755HIGH8.8In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement fil...
CVE-2019-5105HIGH7.5An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solu...
CVE-2019-15796MEDIUM4.7Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py...
CVE-2019-15795MEDIUM4.7python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/...
CVE-2019-18626MEDIUM4.3Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an...
CVE-2019-7630HIGH7.2An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instr...
CVE-2019-7245HIGH7.2An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z before 2.23.0. The vulnerable driver exposes a wrmsr instructi...
CVE-2019-7244HIGH7.2An issue was discovered in kerneld.sys in AIDA64 before 5.99. The vulnerable driver exposes a wrmsr instruction via IOCT...
CVE-2019-7240HIGH7.2An issue was discovered in WinRing0x64.sys in Moo0 System Monitor 1.83. The vulnerable driver exposes a wrmsr instructio...
CVE-2019-20633MEDIUM5.5GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c t...
CVE-2019-19127HIGH8.1An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its de...
CVE-2019-4001HIGH7.8Improper input validation in Druva inSync Client 6.5.0 allows a local, authenticated attacker to execute arbitrary NodeJ...
CVE-2019-19347Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2019-20625LOW3.3An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs dri...
CVE-2019-20624MEDIUM5.3An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now