2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5242 | — | — | 1.0% | Jun 6, 2019 | There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can t... |
| CVE-2019-5241 | — | — | 0.8% | Jun 6, 2019 | There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker... |
| CVE-2019-5219 | — | — | 0.5% | Jun 6, 2019 | There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0... |
| CVE-2019-5216 | — | — | 0.7% | Jun 6, 2019 | There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0... |
| CVE-2019-5214 | — | — | 0.6% | Jun 6, 2019 | There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than A... |
| CVE-2019-12732 | — | — | 0.8% | Jun 6, 2019 | The Chartkick gem through 3.1.0 for Ruby allows XSS. |
| CVE-2019-12134 | — | — | 1.4% | Jun 6, 2019 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a ... |
| CVE-2019-11080 | — | — | 14.2% | Jun 6, 2019 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2... |
| CVE-2019-9158 | — | — | 1.0% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control. |
| CVE-2019-9157 | — | — | 0.7% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure. |
| CVE-2019-9156 | — | — | 3.2% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection. |
| CVE-2019-8385 | — | — | 19.6% | Jun 5, 2019 | An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca... |
| CVE-2019-6800 | — | — | 1.3% | Jun 5, 2019 | In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over ... |
| CVE-2019-9189 | — | — | 11.6% | Jun 5, 2019 | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when ... |
| CVE-2019-9187 | — | — | 1.7% | Jun 5, 2019 | ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact a... |
| CVE-2019-5394 | — | — | 0.3% | Jun 5, 2019 | The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system ... |
| CVE-2019-12276 | — | — | 53.7% | Jun 5, 2019 | A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows... |
| CVE-2019-12196 | — | — | 69.1% | Jun 5, 2019 | A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3... |
| CVE-2019-11988 | — | — | 1.4% | Jun 5, 2019 | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5. |
| CVE-2019-11987 | — | — | 0.3% | Jun 5, 2019 | A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of pri... |
| CVE-2019-11226 | — | — | 0.9% | Jun 5, 2019 | CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News. |
| CVE-2019-9642 | — | — | 2.4% | Jun 5, 2019 | An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possib... |
| CVE-2019-9548 | — | — | 1.5% | Jun 5, 2019 | Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control. |
| CVE-2019-12555 | — | — | 1.2% | Jun 5, 2019 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (... |
| CVE-2019-12554 | — | — | 1.2% | Jun 5, 2019 | In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now