2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-0715MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-0714MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-3637MEDIUM6.7Privilege Escalation vulnerability in McAfee FRP 5.x prior to 5.1.0.209 allows local users to gain elevated privileges v...
CVE-2019-3635MEDIUM6.5Exfiltration of Data in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows attackers to obtain sensitive data via...
CVE-2019-14973MEDIUM6.5_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because ...
CVE-2019-9516MEDIUM6.5Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker se...
CVE-2019-13416MEDIUM6.5Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are alwa...
CVE-2019-13415MEDIUM6.5Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain...
CVE-2019-10929MEDIUM5.9A vulnerability has been identified in SIMATIC CP 1626 (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC (i...
CVE-2019-10928MEDIUM6.6A vulnerability has been identified in SCALANCE SC-600 (V2.0). An authenticated attacker with access to port 22/tcp as w...
CVE-2019-10927MEDIUM6.5A vulnerability has been identified in SCALANCE SC-600 (V2.0), SCALANCE XB-200 (V4.1), SCALANCE XC-200 (V4.1), SCALANCE ...
CVE-2019-13420MEDIUM5.9Search Guard versions before 21.0 had an timing side channel issue when using the internal user database.
CVE-2019-14981MEDIUM6.5In ImageMagick 7.x before 7.0.8-41 and 6.x before 6.9.10-41, there is a divide-by-zero vulnerability in the MeanShiftIma...
CVE-2019-14980MEDIUM6.5In ImageMagick 7.x before 7.0.8-42 and 6.x before 6.9.10-42, there is a use after free vulnerability in the UnmapBlob fu...
CVE-2019-13417MEDIUM5.3Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fie...
CVE-2019-14949MEDIUM6.1The wp-database-backup plugin before 5.1.2 for WordPress has XSS.
CVE-2019-14948MEDIUM5.4The woocommerce-product-addon plugin before 18.4 for WordPress has XSS via an import of a new meta data structure.
CVE-2019-14807MEDIUM6.1In the MobileFrontend extension 1.31 through 1.33 for MediaWiki, XSS exists within the edit summary field in includes/sp...
CVE-2019-11274MEDIUM6.1Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker...
CVE-2019-14433MEDIUM6.5An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request ...
CVE-2019-12265MEDIUM5.3Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPN...
CVE-2019-11776MEDIUM6.1In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the p...
CVE-2019-14796MEDIUM5.4The mq-woocommerce-products-price-bulk-edit (aka Woocommerce Products Price Bulk Edit) plugin 2.0 for WordPress allows X...
CVE-2019-14799MEDIUM6.1The FV Flowplayer Video Player plugin before 7.3.14.727 for WordPress allows email subscription XSS.
CVE-2019-14787MEDIUM5.4The Tribulant Newsletters plugin before 4.6.19 for WordPress allows XSS via the wp-admin/admin-ajax.php?action=newslette...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now