2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6195MEDIUM4.8An authorization bypass exists in Lenovo XClarity Controller (XCC) versions prior to 3.08 CDI340V, 3.01 TEI392O, 1.71 PS...
CVE-2019-6194MEDIUM5.5An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prio...
CVE-2019-6193HIGH7.5An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 tha...
CVE-2019-6190MEDIUM5.5Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Deskto...
CVE-2019-20046CRITICAL9.8The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and pri...
CVE-2019-20045HIGH7.5The Synergy Systems & Solutions PLC & RTU system has a vulnerability in HUSKY RTU 6049-E70 firmware versions 5.0 and pri...
CVE-2019-19879HIGH7.5HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2.
CVE-2019-19765Rejected reason: Unused CVE for 2019
CVE-2019-19764Rejected reason: Unused CVE for 2019
CVE-2019-19763Rejected reason: Unused CVE for 2019
CVE-2019-19762Rejected reason: Unused CVE for 2019
CVE-2019-19758MEDIUM6.1A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior co...
CVE-2019-19757MEDIUM5.4An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) base...
CVE-2019-20455MEDIUM5.9Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
CVE-2019-20454HIGH7.5An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match speciall...
CVE-2019-3998MEDIUM5.5Authentication bypass using an alternate path or channel in SimpliSafe SS3 firmware 1.4 allows a local, unauthenticated ...
CVE-2019-14598MEDIUM6.7Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 t...
CVE-2019-10785MEDIUM6.1dojox is vulnerable to Cross-site Scripting in all versions before version 1.16.1, 1.15.2, 1.14.5, 1.13.6, 1.12.7 and 1....
CVE-2019-4666LOW2.3IBM UrbanCode Deploy (UCD) 7.0.3 and IBM UrbanCode Build 6.1.5 could allow a local user to obtain sensitive information ...
CVE-2019-4592HIGH7.5IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operati...
CVE-2019-18791MEDIUM5.4Lexmark printer MS812 and multiple older generation Lexmark devices have a stored XSS vulnerability in the embedded web ...
CVE-2019-2200HIGH7.3In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permiss...
CVE-2019-14652MEDIUM6.1explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certa...
CVE-2019-5322HIGH7.5A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 381...
CVE-2019-18915HIGH7.8A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now