2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18273MEDIUM4.8OSIsoft PI Vision, PI Vision 2017 R2 and PI Vision 2017 R2 SP1. The affected product is vulnerable to cross-site scripti...
CVE-2019-18271HIGH8.8OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request f...
CVE-2019-18244MEDIUM4.7In OSIsoft PI System multiple products and versions, a local attacker could view sensitive information in log files when...
CVE-2019-15961MEDIUM6.5A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could a...
CVE-2019-9510HIGH7.8A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne...
CVE-2019-9493CRITICAL9.8The MyCar Controls of AutoMobility Distribution Inc., mobile application contains hard-coded admin credentials. A remote...
CVE-2019-16469HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. ...
CVE-2019-16468HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Succe...
CVE-2019-16467MEDIUM6.1Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. ...
CVE-2019-16466MEDIUM6.1Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have a reflected cross-site scripting vulnerability. ...
CVE-2019-18412HIGH7.5JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2019-17150Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was accidentally assigned. Notes: All CVE user...
CVE-2019-17149Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was accidentally assigned. Notes: All CVE user...
CVE-2019-16784HIGH7.8In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic...
CVE-2019-3981LOW3.7MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client'...
CVE-2019-13722MEDIUM6.5Inappropriate implementation in WebRTC in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially e...
CVE-2019-13537HIGH7.5The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffe...
CVE-2019-19548HIGH7.8Norton Power Eraser, prior to 5.3.0.67, may be susceptible to a privilege escalation vulnerability, which is a type of i...
CVE-2019-12398MEDIUM4.8In Apache Airflow before 1.10.5 when running with the "classic" UI, a malicious admin user could edit the state of objec...
CVE-2019-10995HIGH8.8ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during t...
CVE-2019-12399HIGH7.5When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more ...
CVE-2019-0219CRITICAL9.8A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's we...
CVE-2019-20144MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 10.8 through 12.6.1. It has Incorre...
CVE-2019-20143MEDIUM5.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.6. It has Incorrect Access Contr...
CVE-2019-20142MEDIUM4.3An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Deni...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now