2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-11712POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirem...
CVE-2019-11702A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a kn...
CVE-2019-11701The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default...
CVE-2019-11700A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user a...
CVE-2019-11699A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page nav...
CVE-2019-11698If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently ...
CVE-2019-11697If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed...
CVE-2019-11696Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download...
CVE-2019-11695A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when i...
CVE-2019-11694A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a ...
CVE-2019-11693The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could ...
CVE-2019-11692A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, ...
CVE-2019-11691A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main t...
CVE-2019-1010221LineageOS 16.0 and earlier is affected by: Incorrect Access Control. The impact is: The property checked by `adb root` c...
CVE-2019-1010209GoUrl.io GoURL Wordpress Plugin 1.4.13 and earlier is affected by: CWE-434. The impact is: unauthenticated/unzuthorized ...
CVE-2019-1010208IDRIX, Truecrypt Veracrypt, Truecrypt Prior to 1.23-Hotfix-1 (Veracrypt), all versions (Truecrypt) is affected by: Buffe...
CVE-2019-1010207Genetechsolutions Pie Register 3.0.15 is affected by: Cross Site Scripting (XSS). The impact is: Stealing of session coo...
CVE-2019-1010205LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact...
CVE-2019-1010202Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component ...
CVE-2019-1010171Jsish 2.4.83 2.0483 is affected by: Nullpointer dereference. The impact is: denial of service. The component is: functio...
CVE-2019-1010170Jsish 2.4.77 2.0477 is affected by: Use After Free. The impact is: denial of service. The component is: function Jsi_Obj...
CVE-2019-1010169Jsish 2.4.77 2.0477 is affected by: Out-of-bounds Read. The impact is: denial of service. The component is: function lex...
CVE-2019-1010162jsish 2.4.74 2.0474 is affected by: CWE-476: NULL Pointer Dereference. The impact is: denial of service. The component i...
CVE-2019-1010156Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-1010155. Reason: This candidate is a duplicate o...
CVE-2019-1010153zzcms 8.3 and earlier is affected by: SQL Injection. The impact is: sql inject. The component is: zs/subzs.php.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now