2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-5295——Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass ...
CVE-2019-5242——There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can t...
CVE-2019-5241——There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker...
CVE-2019-5219——There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0...
CVE-2019-5216——There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0...
CVE-2019-5214——There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than A...
CVE-2019-12732——The Chartkick gem through 3.1.0 for Ruby allows XSS.
CVE-2019-12134——CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a ...
CVE-2019-11080——Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2...
CVE-2019-9158——Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
CVE-2019-9157——Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
CVE-2019-9156——Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
CVE-2019-8385——An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca...
CVE-2019-6800——In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over ...
CVE-2019-9189——Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when ...
CVE-2019-9187——ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact a...
CVE-2019-5394——The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system ...
CVE-2019-12276——A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows...
CVE-2019-12196——A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3...
CVE-2019-11988——A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
CVE-2019-11987——A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of pri...
CVE-2019-11226——CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
CVE-2019-9642——An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possib...
CVE-2019-9548——Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
CVE-2019-12555——In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now