2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-11752HIGH8.8It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a ...
CVE-2019-11751HIGH8.8Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as ...
CVE-2019-11746HIGH8.8A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This...
CVE-2019-11740HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox ...
CVE-2019-11736HIGH7The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, ...
CVE-2019-11735HIGH8.8Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of t...
CVE-2019-9853HIGH7.8LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings,...
CVE-2019-8075HIGH7.5Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful ex...
CVE-2019-8072HIGH7.5ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. S...
CVE-2019-16921HIGH7.5In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initializ...
CVE-2019-16902HIGH7.5In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an...
CVE-2019-11279HIGH8.8CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requ...
CVE-2019-15862HIGH7.5An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload fil...
CVE-2019-11278HIGH8.8CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'clie...
CVE-2019-16667HIGH8.8diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi...
CVE-2019-6175HIGH7.5A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow conf...
CVE-2019-6161HIGH7.5An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB ...
CVE-2019-16869HIGH7.5Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked...
CVE-2019-12091HIGH7.8The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ...
CVE-2019-10882HIGH7.8The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ...
CVE-2019-10097HIGH7.2In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using t...
CVE-2019-0203HIGH7.5In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ...
CVE-2019-14844HIGH7.5A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash ...
CVE-2019-16901HIGH7.5Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x00000000...
CVE-2019-16900HIGH7.5Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now