2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-5242There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can t...
CVE-2019-5241There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker...
CVE-2019-5219There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0...
CVE-2019-5216There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0...
CVE-2019-5214There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than A...
CVE-2019-12732The Chartkick gem through 3.1.0 for Ruby allows XSS.
CVE-2019-12134CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a ...
CVE-2019-11080Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2...
CVE-2019-9158Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
CVE-2019-9157Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
CVE-2019-9156Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
CVE-2019-8385An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca...
CVE-2019-6800In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over ...
CVE-2019-9189Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when ...
CVE-2019-9187ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact a...
CVE-2019-5394The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system ...
CVE-2019-12276A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows...
CVE-2019-12196A SQL injection vulnerability in /client/api/json/v2/nfareports/compareReport in Zoho ManageEngine NetFlow Analyzer 12.3...
CVE-2019-11988A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
CVE-2019-11987A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of pri...
CVE-2019-11226CMS Made Simple 2.2.10 has XSS via the m1_name parameter in "Add Article" under Content -> Content Manager -> News.
CVE-2019-9642An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possib...
CVE-2019-9548Citrix Application Delivery Management (ADM) 12.1.x before 12.1.50.33 has Incorrect Access Control.
CVE-2019-12555In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the SubStr function (...
CVE-2019-12554In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now