2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-2866HIGH8.2Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2865HIGH7.5Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2864HIGH7.5Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2859HIGH8.8Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th...
CVE-2019-2832HIGH8.8Vulnerability in the Oracle Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environ...
CVE-2019-2822HIGH7.5Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Cluster). Supported ver...
CVE-2019-2800HIGH7.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that...
CVE-2019-2792HIGH7.3Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filter...
CVE-2019-14243HIGH7.5headerv2.go in mastercactapus proxyprotocol before 0.0.2, as used in the mastercactapus caddy-proxyprotocol plugin throu...
CVE-2019-9818HIGH8.3A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can ...
CVE-2019-9811HIGH8.3As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack a...
CVE-2019-11723HIGH7.5A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the b...
CVE-2019-11711HIGH8.8When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages o...
CVE-2019-11707HIGH8.8A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow...
CVE-2019-11706HIGH7.5A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when pro...
CVE-2019-12327HIGH7.2Hardcoded credentials in the Akuvox R50P VoIP phone 50.0.6.156 allow an attacker to get access to the device via telnet....
CVE-2019-1010218HIGH7.5Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CW...
CVE-2019-12326HIGH7.2Missing file and path validation in the ringtone upload function of the Akuvox R50P VoIP phone 50.0.6.156 allows an atta...
CVE-2019-12325HIGH8.8The Htek UC902 VoIP phone web management interface contains several buffer overflow vulnerabilities in the firmware vers...
CVE-2019-12324HIGH7.2A command injection (missing input validation) issue in the IP address field for the logging server in the configuration...
CVE-2019-4267HIGH7.8The IBM Spectrum Protect 7.1 and 8.1 Backup-Archive Client is vulnerable to a buffer overflow. This could allow executio...
CVE-2019-14213HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the repeated release of th...
CVE-2019-14211HIGH7.5An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash due to the lack of proper validat...
CVE-2019-14206HIGH7.5An Arbitrary File Deletion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote a...
CVE-2019-14205HIGH7.5A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attac...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now