2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14905MEDIUM5.6A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and ear...
CVE-2019-10180MEDIUM4.8A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sani...
CVE-2019-14880CRITICAL9.1A vulnerability was found in Moodle versions 3.7 before 3.7.3, 3.6 before 3.6.7, 3.5 before 3.5.9 and earlier. OAuth 2 p...
CVE-2019-2391MEDIUM5.4Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected ...
CVE-2019-9509MEDIUM5.4The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to reflected XSS in an HTTP POST paramet...
CVE-2019-9508LOW3.5The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to stored XSS. A remote attacker authent...
CVE-2019-9507HIGH7.2The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the applica...
CVE-2019-19913MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, there is stored XSS via the Trackers Title parameter.
CVE-2019-19912MEDIUM4.8In Intland codeBeamer ALM 9.5 and earlier, a cross-site scripting (XSS) vulnerability in the Upload Flash File feature a...
CVE-2019-19606CRITICAL9.8X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary...
CVE-2019-19605CRITICAL9.8X-Plane before 11.41 allows Arbitrary Memory Write via crafted network packets, which could cause a denial of service or...
CVE-2019-20634LOW3.7An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email he...
CVE-2019-17561HIGH7.5The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded...
CVE-2019-17560CRITICAL9.1The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This...
CVE-2019-7755HIGH8.8In webERP 4.15, the Import Bank Transactions function fails to sanitize the content of imported MT940 bank statement fil...
CVE-2019-5105HIGH7.5An exploitable memory corruption vulnerability exists in the Name Service Client functionality of 3S-Smart Software Solu...
CVE-2019-15796MEDIUM4.7Python-apt doesn't check if hashes are signed in `Version.fetch_binary()` and `Version.fetch_source()` of apt/package.py...
CVE-2019-15795MEDIUM4.7python-apt only checks the MD5 sums of downloaded files in `Version.fetch_binary()` and `Version.fetch_source()` of apt/...
CVE-2019-18626MEDIUM4.3Harris Ormed Self Service before 2019.1.4 allows an authenticated user to view W-2 forms belonging to other users via an...
CVE-2019-7630HIGH7.2An issue was discovered in gdrv.sys in Gigabyte APP Center before 19.0227.1. The vulnerable driver exposes a wrmsr instr...
CVE-2019-7245HIGH7.2An issue was discovered in GPU-Z.sys in TechPowerUp GPU-Z before 2.23.0. The vulnerable driver exposes a wrmsr instructi...
CVE-2019-7244HIGH7.2An issue was discovered in kerneld.sys in AIDA64 before 5.99. The vulnerable driver exposes a wrmsr instruction via IOCT...
CVE-2019-7240HIGH7.2An issue was discovered in WinRing0x64.sys in Moo0 System Monitor 1.83. The vulnerable driver exposes a wrmsr instructio...
CVE-2019-20633MEDIUM5.5GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c t...
CVE-2019-19127HIGH8.1An authentication bypass vulnerability is present in the standalone SITS:Vision 9.7.0 component of Tribal SITS in its de...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now