2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13368 | — | — | — | Jul 8, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13367 | — | — | — | Jul 8, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-12927 | — | — | 0.9% | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because t... |
| CVE-2019-12926 | — | — | 0.9% | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it ... |
| CVE-2019-12925 | — | — | 1.8% | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated user... |
| CVE-2019-12924 | — | — | 0.9% | Jul 8, 2019 | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploite... |
| CVE-2019-12923 | — | — | 0.6% | Jul 8, 2019 | In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not imp... |
| CVE-2019-12930 | — | — | 1.1% | Jul 8, 2019 | A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to v... |
| CVE-2019-9630 | — | — | 1.4% | Jul 8, 2019 | Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions o... |
| CVE-2019-9629 | — | — | 1.5% | Jul 8, 2019 | Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed crede... |
| CVE-2019-2119 | — | — | 0.1% | Jul 8, 2019 | In multiple functions of key_store_service.cpp, there is a possible Information Disclosure due to improper locking. This... |
| CVE-2019-2118 | — | — | 0.2% | Jul 8, 2019 | In various functions of Parcel.cpp, there are uninitialized or partially initialized stack variables. These could lead t... |
| CVE-2019-2117 | — | — | 0.1% | Jul 8, 2019 | In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permis... |
| CVE-2019-2116 | — | — | 0.8% | Jul 8, 2019 | In save_attr_seq of sdp_discovery.cc, there is a possible out-of-bound read due to a missing bounds check. This could le... |
| CVE-2019-2113 | — | — | 0.1% | Jul 8, 2019 | In setup wizard there is a bypass of some checks when wifi connection is skipped. This could lead to factory reset prote... |
| CVE-2019-2112 | — | — | 0.2% | Jul 8, 2019 | In several functions of alarm.cc, there is possible memory corruption due to a use after free. This could lead to local ... |
| CVE-2019-2111 | — | — | 0.8% | Jul 8, 2019 | In loop of DnsTlsSocket.cpp, there is a possible heap memory corruption due to a use after free. This could lead to remo... |
| CVE-2019-2109 | — | — | 1.2% | Jul 8, 2019 | In MakeMPEG4VideoCodecSpecificData of AVIExtractor.cpp, there is a possible out of bounds write due to an incorrect boun... |
| CVE-2019-2107 | — | — | 8.9% | Jul 8, 2019 | In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th... |
| CVE-2019-2106 | — | — | 1.2% | Jul 8, 2019 | In ihevcd_sao_shift_ctb of ihevcd_sao.c, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2019-2105 | — | — | 0.7% | Jul 8, 2019 | In FileInputStream::Read of file_input_stream.cc, there is a possible memory corruption due to uninitialized data. This ... |
| CVE-2019-2104 | — | — | 0.2% | Jul 8, 2019 | In HIDL, safe_union, and other C++ structs/unions being sent to application processes, there are uninitialized fields. T... |
| CVE-2019-10973 | — | — | 2.4% | Jul 8, 2019 | Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveragi... |
| CVE-2019-13354 | — | — | 3.3% | Jul 8, 2019 | The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a... |
| CVE-2019-12174 | — | — | 0.4% | Jul 8, 2019 | hide.me before 2.4.4 on macOS suffers from a privilege escalation vulnerability in the connectWithExecutablePath:configF... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now