2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6825 | HIGH | 7.8 | 1.2% | Jul 15, 2019 | A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which... |
| CVE-2019-6822 | HIGH | 7.8 | 3.7% | Jul 15, 2019 | A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code executio... |
| CVE-2019-1132 | HIGH | 7.8 | 9.8% | Jul 15, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2019-1130 | HIGH | 7.8 | 2.3% | Jul 15, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li... |
| CVE-2019-1129 | HIGH | 7.8 | 1.8% | Jul 15, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li... |
| CVE-2019-0887 | HIGH | 8 | 71.0% | Jul 15, 2019 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an ... |
| CVE-2019-0880 | HIGH | 7.8 | 2.4% | Jul 15, 2019 | A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 E... |
| CVE-2019-1010006 | HIGH | 7.8 | 2.1% | Jul 15, 2019 | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/ti... |
| CVE-2019-13602 | HIGH | 7.8 | 2.1% | Jul 14, 2019 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 all... |
| CVE-2019-5629 | HIGH | 7.8 | 0.9% | Jul 13, 2019 | Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL sear... |
| CVE-2019-8998 | HIGH | 7.8 | 0.2% | Jul 12, 2019 | An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the ... |
| CVE-2019-13567 | HIGH | 8.8 | 3.8% | Jul 12, 2019 | The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-134... |
| CVE-2019-10931 | HIGH | 7.5 | 1.5% | Jul 11, 2019 | A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respe... |
| CVE-2019-10915 | HIGH | 7.8 | 0.9% | Jul 11, 2019 | A vulnerability has been identified in TIA Administrator (All versions < V1.0 SP1 Upd1). The integrated configuration we... |
| CVE-2019-4193 | HIGH | 7.5 | 2.1% | Jul 11, 2019 | IBM Jazz for Service Management 1.1.3 and 1.1.3.2 stores sensitive information in URL parameters. This may lead to infor... |
| CVE-2019-0053 | HIGH | 7.8 | 0.6% | Jul 11, 2019 | Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffe... |
| CVE-2019-0052 | HIGH | 7.5 | 1.8% | Jul 11, 2019 | The srxpfe process may crash on SRX Series services gateways when the UTM module processes a specific fragmented HTTP pa... |
| CVE-2019-0049 | HIGH | 7.5 | 1.5% | Jul 11, 2019 | On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a cert... |
| CVE-2019-9886 | HIGH | 7.5 | 2.2% | Jul 11, 2019 | Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login... |
| CVE-2019-12527 | HIGH | 8.8 | 50.5% | Jul 11, 2019 | An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid ... |
| CVE-2019-10193 | HIGH | 7.2 | 23.7% | Jul 11, 2019 | A stack-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x ... |
| CVE-2019-10192 | HIGH | 7.2 | 26.0% | Jul 11, 2019 | A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x b... |
| CVE-2019-10135 | HIGH | 7.2 | 1.9% | Jul 11, 2019 | A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1. Insecure use of the y... |
| CVE-2019-13563 | HIGH | 8.8 | 1.0% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow CSRF for the entire management console. |
| CVE-2019-10351 | HIGH | 8.8 | 1.6% | Jul 11, 2019 | Jenkins Caliper CI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now