2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-13368Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13367Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-12927MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because t...
CVE-2019-12926MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it ...
CVE-2019-12925MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated user...
CVE-2019-12924MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploite...
CVE-2019-12923In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not imp...
CVE-2019-12930A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to v...
CVE-2019-9630Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions o...
CVE-2019-9629Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed crede...
CVE-2019-2119In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This...
CVE-2019-2118In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t...
CVE-2019-2117In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permis...
CVE-2019-2116In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could le...
CVE-2019-2113In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset prote...
CVE-2019-2112In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local ...
CVE-2019-2111In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remo...
CVE-2019-2109In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect boun...
CVE-2019-2107In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th...
CVE-2019-2106In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2019-2105In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This ...
CVE-2019-2104In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T...
CVE-2019-10973Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveragi...
CVE-2019-13354The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a...
CVE-2019-12174hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configF...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now