2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16958MEDIUM5.4Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web scri...
CVE-2019-20934MEDIUM5.3An issue was discovered in the Linux kernel before 5.2.6. On NUMA systems, the Linux fair scheduler has a use-after-free...
CVE-2019-19877MEDIUM5.3An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to sensitive in...
CVE-2019-14587MEDIUM6.5Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2019-2393MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-2392MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-20924MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which t...
CVE-2019-20923MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-14562MEDIUM5.5Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of...
CVE-2019-14553MEDIUM4.9Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network a...
CVE-2019-19562MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to d...
CVE-2019-19560MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to d...
CVE-2019-19556MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to dev...
CVE-2019-7356MEDIUM5.4Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
CVE-2019-4563MEDIUM5.3IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attack...
CVE-2019-4547MEDIUM5.3IBM Security Directory Server 6.4.0 generates an error message that includes sensitive information about its environment...
CVE-2019-8901MEDIUM6.5This issue was addressed by verifying host keys when connecting to a previously-known SSH server. This issue is fixed in...
CVE-2019-8898MEDIUM4.3An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improve...
CVE-2019-8858MEDIUM5.3A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.1, Security Upda...
CVE-2019-8855MEDIUM6.3An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Catalina 10.15. A malic...
CVE-2019-8853MEDIUM5.5A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.4, Securi...
CVE-2019-8850MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15, iOS 13....
CVE-2019-8796MEDIUM5.3A logic issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.1, Security Update 201...
CVE-2019-8664MEDIUM6.5An input validation issue was addressed with improved input validation. This issue is fixed in iOS 12.3, watchOS 5.2.1. ...
CVE-2019-8839MEDIUM5.5A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.2, Security U...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now