2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9086 | — | — | 1.6% | Jun 7, 2019 | HotelDruid before v2.3.1 has SQL Injection via the /visualizza_tabelle.php anno parameter. |
| CVE-2019-9084 | — | — | 1.7% | Jun 7, 2019 | In Hoteldruid before 2.3.1, a division by zero was discovered in $num_tabelle in tab_tariffe.php (aka the numtariffa1 pa... |
| CVE-2019-3956 | — | — | 1.6% | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the ... |
| CVE-2019-12506 | — | — | 1.3% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remot... |
| CVE-2019-12505 | — | — | 1.3% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP1001 v1.3C is prone to keyst... |
| CVE-2019-12504 | — | — | 1.9% | Jun 7, 2019 | Due to unencrypted and unauthenticated data communication, the wireless presenter Inateck WP2002 is prone to keystroke i... |
| CVE-2019-5441 | — | — | — | Jun 7, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12739. Reason: This candidate is a reservation d... |
| CVE-2019-3955 | — | — | 19.1% | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains a unauthenticated remote heap overflow due to the serv... |
| CVE-2019-2102 | — | — | 0.3% | Jun 7, 2019 | In the Bluetooth Low Energy (BLE) specification, there is a provided example Long Term Key (LTK). If a BLE device were t... |
| CVE-2019-2099 | — | — | 0.6% | Jun 7, 2019 | In nfa_rw_store_ndef_rx_buf of nfa_rw_act.cc, there is a possible out-of-bound write due to a missing bounds check. This... |
| CVE-2019-2098 | — | — | 0.2% | Jun 7, 2019 | In areNotificationsEnabledForPackage of NotificationManagerService.java, there is a possible permissions bypass due to a... |
| CVE-2019-2097 | — | — | 1.3% | Jun 7, 2019 | In HAliasAnalyzer.Query of hydrogen-alias-analysis.h, there is possible memory corruption due to type confusion. This co... |
| CVE-2019-2096 | — | — | 0.2% | Jun 7, 2019 | In EffectRelease of EffectBundle.cpp, there is a possible memory corruption due to a double free. This could lead to loc... |
| CVE-2019-2095 | — | — | 0.7% | Jun 7, 2019 | In callGenIDChangeListeners and related functions of SkPixelRef.cpp, there is a possible use after free due to a race co... |
| CVE-2019-2094 | — | — | 1.1% | Jun 7, 2019 | In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing bounds checks. This ... |
| CVE-2019-2093 | — | — | 1.2% | Jun 7, 2019 | In huff_dec_1D of nlc_dec.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to... |
| CVE-2019-2092 | — | — | 0.2% | Jun 7, 2019 | In isSeparateProfileChallengeAllowed of DevicePolicyManagerService.java, there is a possible permissions bypass due to a... |
| CVE-2019-2091 | — | — | 0.2% | Jun 7, 2019 | In GetPermittedAccessibilityServicesForUser of DevicePolicyManagerService.java, there is a possible permissions bypass d... |
| CVE-2019-2090 | — | — | 0.1% | Jun 7, 2019 | In isPackageDeviceAdminOnAnyUser of PackageManagerService.java, there is a possible permissions bypass due to a missing ... |
| CVE-2019-12779 | — | — | 0.7% | Jun 7, 2019 | libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable fil... |
| CVE-2019-12601 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 3 of 3). |
| CVE-2019-12600 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 2 of 3). |
| CVE-2019-12599 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.10.x before 7.10.17 and 7.11.x before 7.11.5 allows SQL Injection. |
| CVE-2019-12598 | — | — | 1.1% | Jun 7, 2019 | SuiteCRM 7.8.x before 7.8.30, 7.10.x before 7.10.17, and 7.11.x before 7.11.5 allows SQL Injection (issue 1 of 3). |
| CVE-2019-3477 | — | — | 0.6% | Jun 7, 2019 | Micro Focus Solution Business Manager versions prior to 11.4.2 is susceptible to open redirect. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now