2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5809 | HIGH | 8.8 | 1.5% | Jun 27, 2019 | Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the... |
| CVE-2019-5808 | HIGH | 8.8 | 1.8% | Jun 27, 2019 | Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap co... |
| CVE-2019-5807 | HIGH | 8.8 | 1.4% | Jun 27, 2019 | Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-5806 | HIGH | 8.8 | 1.3% | Jun 27, 2019 | Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially ex... |
| CVE-2019-3628 | HIGH | 8.8 | 1.0% | Jun 27, 2019 | Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain ... |
| CVE-2019-7227 | HIGH | 7.3 | 8.5% | Jun 27, 2019 | In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD .... |
| CVE-2019-7226 | HIGH | 8.8 | 5.3% | Jun 27, 2019 | The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication a... |
| CVE-2019-7228 | HIGH | 8.8 | 3.7% | Jun 27, 2019 | The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting... |
| CVE-2019-4252 | HIGH | 7.5 | 3.4% | Jun 27, 2019 | IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directorie... |
| CVE-2019-1621 | HIGH | 7.5 | 29.8% | Jun 27, 2019 | A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe... |
| CVE-2019-10154 | HIGH | 7.5 | 1.3% | Jun 26, 2019 | A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current... |
| CVE-2019-12981 | HIGH | 8.8 | 1.3% | Jun 26, 2019 | Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape.... |
| CVE-2019-12979 | HIGH | 7.8 | 2.4% | Jun 26, 2019 | ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/im... |
| CVE-2019-10164 | HIGH | 8.8 | 3.7% | Jun 26, 2019 | PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any ... |
| CVE-2019-4241 | HIGH | 7.8 | 0.4% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authent... |
| CVE-2019-4235 | HIGH | 7.5 | 1.5% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, ... |
| CVE-2019-4224 | HIGH | 8.8 | 1.4% | Jun 26, 2019 | IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall... |
| CVE-2019-3569 | HIGH | 7.5 | 1.5% | Jun 26, 2019 | HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i... |
| CVE-2019-6169 | HIGH | 7.5 | 0.8% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP. |
| CVE-2019-6166 | HIGH | 8.8 | 0.5% | Jun 26, 2019 | A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. |
| CVE-2019-11272 | HIGH | 7.3 | 1.4% | Jun 26, 2019 | Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex... |
| CVE-2019-6329 | HIGH | 7.8 | 1.6% | Jun 25, 2019 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d... |
| CVE-2019-4145 | HIGH | 7.1 | 0.4% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user ... |
| CVE-2019-4135 | HIGH | 8.8 | 1.5% | Jun 25, 2019 | IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated u... |
| CVE-2019-12817 | HIGH | 7 | 0.4% | Jun 25, 2019 | arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now