2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1145 | HIGH | 8.8 | 13.1% | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2019-1144 | HIGH | 8.8 | 13.1% | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2019-1140 | HIGH | 8.8 | 3.8% | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-1133 | HIGH | 7.5 | 3.3% | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ... |
| CVE-2019-1057 | HIGH | 7.5 | 3.1% | Aug 14, 2019 | A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An ... |
| CVE-2019-13030 | HIGH | 8.2 | 1.9% | Aug 14, 2019 | eQ-3 Homematic CCU3 AddOn 'Mediola NEO Server for Homematic CCU3' prior to 2.4.5 allows uncontrolled admin access to sta... |
| CVE-2019-0965 | HIGH | 7.6 | 1.3% | Aug 14, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from... |
| CVE-2019-0720 | HIGH | 8 | 3.8% | Aug 14, 2019 | A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali... |
| CVE-2019-9583 | HIGH | 8.2 | 1.9% | Aug 14, 2019 | eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point f... |
| CVE-2019-9506 | HIGH | 8.1 | 2.7% | Aug 14, 2019 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do... |
| CVE-2019-3639 | HIGH | 7.1 | 1.2% | Aug 14, 2019 | Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote ... |
| CVE-2019-10201 | HIGH | 8.1 | 0.7% | Aug 14, 2019 | It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke... |
| CVE-2019-10199 | HIGH | 8.8 | 0.5% | Aug 14, 2019 | It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a... |
| CVE-2019-8062 | HIGH | 7.8 | 3.2% | Aug 14, 2019 | Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful e... |
| CVE-2019-15046 | HIGH | 7.5 | 5.3% | Aug 14, 2019 | Zoho ManageEngine ServiceDesk Plus 10 before 10509 allows unauthenticated sensitive information leakage during Fail Over... |
| CVE-2019-9518 | HIGH | 7.5 | 24.8% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The a... |
| CVE-2019-9517 | HIGH | 7.5 | 27.9% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of s... |
| CVE-2019-9515 | HIGH | 7.5 | 87.8% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker... |
| CVE-2019-9514 | HIGH | 7.5 | 82.8% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker op... |
| CVE-2019-9513 | HIGH | 7.5 | 82.6% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker c... |
| CVE-2019-9512 | HIGH | 7.5 | 83.4% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker send... |
| CVE-2019-9511 | HIGH | 7.5 | 59.5% | Aug 13, 2019 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential... |
| CVE-2019-11207 | HIGH | 8.8 | 0.7% | Aug 13, 2019 | The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Ma... |
| CVE-2019-12808 | HIGH | 7.8 | 0.4% | Aug 13, 2019 | ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure per... |
| CVE-2019-12807 | HIGH | 7.8 | 1.6% | Aug 13, 2019 | Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now