2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11740 | HIGH | 8.8 | 1.6% | Sep 27, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox ... |
| CVE-2019-11736 | HIGH | 7 | 0.2% | Sep 27, 2019 | The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, ... |
| CVE-2019-11735 | HIGH | 8.8 | 1.2% | Sep 27, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of t... |
| CVE-2019-9853 | HIGH | 7.8 | 3.2% | Sep 27, 2019 | LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings,... |
| CVE-2019-8075 | HIGH | 7.5 | 3.0% | Sep 27, 2019 | Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful ex... |
| CVE-2019-8072 | HIGH | 7.5 | 7.4% | Sep 27, 2019 | ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Security bypass vulnerability. S... |
| CVE-2019-16921 | HIGH | 7.5 | 2.0% | Sep 27, 2019 | In the Linux kernel before 4.17, hns_roce_alloc_ucontext in drivers/infiniband/hw/hns/hns_roce_main.c does not initializ... |
| CVE-2019-16902 | HIGH | 7.5 | 9.7% | Sep 27, 2019 | In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an... |
| CVE-2019-11279 | HIGH | 8.8 | 1.3% | Sep 26, 2019 | CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requ... |
| CVE-2019-15862 | HIGH | 7.5 | 1.5% | Sep 26, 2019 | An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload fil... |
| CVE-2019-11278 | HIGH | 8.8 | 1.3% | Sep 26, 2019 | CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'clie... |
| CVE-2019-16667 | HIGH | 8.8 | 54.5% | Sep 26, 2019 | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi... |
| CVE-2019-6175 | HIGH | 7.5 | 1.7% | Sep 26, 2019 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow conf... |
| CVE-2019-6161 | HIGH | 7.5 | 1.4% | Sep 26, 2019 | An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB ... |
| CVE-2019-16869 | HIGH | 7.5 | 8.4% | Sep 26, 2019 | Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked... |
| CVE-2019-12091 | HIGH | 7.8 | 0.9% | Sep 26, 2019 | The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ... |
| CVE-2019-10882 | HIGH | 7.8 | 0.4% | Sep 26, 2019 | The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts ... |
| CVE-2019-10097 | HIGH | 7.2 | 52.9% | Sep 26, 2019 | In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using t... |
| CVE-2019-0203 | HIGH | 7.5 | 3.4% | Sep 26, 2019 | In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit ... |
| CVE-2019-14844 | HIGH | 7.5 | 4.4% | Sep 26, 2019 | A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash ... |
| CVE-2019-16901 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | Advantech WebAccess/HMI Designer 2.1.9.31 has Exception Handler Chain corruption starting at Unknown Symbol @ 0x00000000... |
| CVE-2019-16900 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | Advantech WebAccess/HMI Designer 2.1.9.31 has a User Mode Write AV starting at MSVCR90!memcpy+0x000000000000015c. |
| CVE-2019-16899 | HIGH | 7.5 | 1.3% | Sep 26, 2019 | In Advantech WebAccess/HMI Designer 2.1.9.31, Data from a Faulting Address controls Code Flow starting at PM_V3!CTagInfo... |
| CVE-2019-16253 | HIGH | 7.8 | 1.2% | Sep 25, 2019 | The Text-to-speech Engine (aka SamsungTTS) application before 3.0.02.7 and 3.0.00.101 for Android allows a local attacke... |
| CVE-2019-12717 | HIGH | 7.8 | 0.4% | Sep 25, 2019 | A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an aut... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now