2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5816HIGH8.8Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potenti...
CVE-2019-5813HIGH8.8Use after free in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corru...
CVE-2019-5811HIGH8.8Incorrect handling of CORS in ServiceWorker in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass ...
CVE-2019-5809HIGH8.8Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the...
CVE-2019-5808HIGH8.8Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap co...
CVE-2019-5807HIGH8.8Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit hea...
CVE-2019-5806HIGH8.8Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially ex...
CVE-2019-3628HIGH8.8Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain ...
CVE-2019-7227HIGH7.3In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ....
CVE-2019-7226HIGH8.8The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication a...
CVE-2019-7228HIGH8.8The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting...
CVE-2019-4252HIGH7.5IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directorie...
CVE-2019-1621HIGH7.5A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2019-10154HIGH7.5A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current...
CVE-2019-12981HIGH8.8Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape....
CVE-2019-12979HIGH7.8ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/im...
CVE-2019-10164HIGH8.8PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any ...
CVE-2019-4241HIGH7.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authent...
CVE-2019-4235HIGH7.5IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, ...
CVE-2019-4224HIGH8.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall...
CVE-2019-3569HIGH7.5HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i...
CVE-2019-6169HIGH7.5A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
CVE-2019-6166HIGH8.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
CVE-2019-11272HIGH7.3Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex...
CVE-2019-6329HIGH7.8HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now