2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5809HIGH8.8Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the...
CVE-2019-5808HIGH8.8Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap co...
CVE-2019-5807HIGH8.8Object lifetime issue in V8 in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit hea...
CVE-2019-5806HIGH8.8Integer overflow in ANGLE in Google Chrome on Windows prior to 74.0.3729.108 allowed a remote attacker to potentially ex...
CVE-2019-3628HIGH8.8Privilege escalation in McAfee Enterprise Security Manager (ESM) 11.x prior to 11.2.0 allows authenticated user to gain ...
CVE-2019-7227HIGH7.3In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ....
CVE-2019-7226HIGH8.8The ABB IDAL HTTP server CGI interface contains a URL that allows an unauthenticated attacker to bypass authentication a...
CVE-2019-7228HIGH8.8The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting...
CVE-2019-4252HIGH7.5IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directorie...
CVE-2019-1621HIGH7.5A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthe...
CVE-2019-10154HIGH7.5A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current...
CVE-2019-12981HIGH8.8Ming (aka libming) 0.4.8 has an "fill overflow" vulnerability in the function SWFShape_setLeftFillStyle in blocks/shape....
CVE-2019-12979HIGH7.8ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/im...
CVE-2019-10164HIGH8.8PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any ...
CVE-2019-4241HIGH7.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authent...
CVE-2019-4235HIGH7.5IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, ...
CVE-2019-4224HIGH8.8IBM PureApplication System 2.2.3.0 through 2.2.5.3 is vulnerable to SQL injection. A remote attacker could send speciall...
CVE-2019-3569HIGH7.5HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious i...
CVE-2019-6169HIGH7.5A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP.
CVE-2019-6166HIGH8.8A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery.
CVE-2019-11272HIGH7.3Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex...
CVE-2019-6329HIGH7.8HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d...
CVE-2019-4145HIGH7.1IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user ...
CVE-2019-4135HIGH8.8IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated u...
CVE-2019-12817HIGH7arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now