2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-6825HIGH7.8A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which...
CVE-2019-6822HIGH7.8A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code executio...
CVE-2019-1132HIGH7.8An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2019-1130HIGH7.8An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li...
CVE-2019-1129HIGH7.8An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li...
CVE-2019-0887HIGH8A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an ...
CVE-2019-0880HIGH7.8A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 E...
CVE-2019-1010006HIGH7.8Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/ti...
CVE-2019-13602HIGH7.8An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 all...
CVE-2019-5629HIGH7.8Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL sear...
CVE-2019-8998HIGH7.8An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the ...
CVE-2019-13567HIGH8.8The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-134...
CVE-2019-10931HIGH7.5A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respe...
CVE-2019-10915HIGH7.8A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration we...
CVE-2019-4193HIGH7.5IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to infor...
CVE-2019-0053HIGH7.8Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffe...
CVE-2019-0052HIGH7.5The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP pa...
CVE-2019-0049HIGH7.5On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a cert...
CVE-2019-9886HIGH7.5Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login...
CVE-2019-12527HIGH8.8An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid ...
CVE-2019-10193HIGH7.2A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x ...
CVE-2019-10192HIGH7.2A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x b...
CVE-2019-10135HIGH7.2A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the y...
CVE-2019-13563HIGH8.8D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console.
CVE-2019-10351HIGH8.8Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now