2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-1145HIGH8.8A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded...
CVE-2019-1144HIGH8.8A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded...
CVE-2019-1140HIGH8.8A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2019-1133HIGH7.5A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2019-1057HIGH7.5A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An ...
CVE-2019-13030HIGH8.2eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to sta...
CVE-2019-0965HIGH7.6A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from...
CVE-2019-0720HIGH8A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali...
CVE-2019-9583HIGH8.2eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point f...
CVE-2019-9506HIGH8.1The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do...
CVE-2019-3639HIGH7.1Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote ...
CVE-2019-10201HIGH8.1It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke...
CVE-2019-10199HIGH8.8It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a...
CVE-2019-8062HIGH7.8Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful e...
CVE-2019-15046HIGH7.5Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over...
CVE-2019-9518HIGH7.5Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The a...
CVE-2019-9517HIGH7.5Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of s...
CVE-2019-9515HIGH7.5Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker...
CVE-2019-9514HIGH7.5Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker op...
CVE-2019-9513HIGH7.5Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker c...
CVE-2019-9512HIGH7.5Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker send...
CVE-2019-9511HIGH7.5Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential...
CVE-2019-11207HIGH8.8The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Ma...
CVE-2019-12808HIGH7.8ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure per...
CVE-2019-12807HIGH7.8Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now