2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11763MEDIUM6.1Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entit...
CVE-2019-11762MEDIUM6.1If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call ar...
CVE-2019-11761MEDIUM5.4By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned in...
CVE-2019-11760HIGH8.8A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploit...
CVE-2019-11759HIGH8.8An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This co...
CVE-2019-11758HIGH8.8Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installe...
CVE-2019-11757HIGH8.8When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequent...
CVE-2019-11756HIGH8.8Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of...
CVE-2019-11745HIGH8.8When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a sm...
CVE-2019-19495CRITICAL9.8The web interface on the Technicolor TC7230 STEB 01.25 is vulnerable to DNS rebinding, which allows a remote attacker to...
CVE-2019-5082CRITICAL9.8An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 ...
CVE-2019-20367CRITICAL9.1nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (s...
CVE-2019-20366MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.
CVE-2019-20365MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.
CVE-2019-20364MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
CVE-2019-20363MEDIUM6.1An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via alias to Manage Store Contents.
CVE-2019-19544HIGH7.8CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows...
CVE-2019-10777CRITICAL9.8In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within th...
CVE-2019-5188MEDIUM6.7A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially c...
CVE-2019-19518CRITICAL9.8CA Automic Sysload 5.6.0 through 6.1.2 contains a vulnerability, related to a lack of authentication on the File Server ...
CVE-2019-17076CRITICAL9.8An issue was discovered in Jamf Pro 9.x and 10.x before 10.15.1. Deserialization of untrusted data when parsing JSON in ...
CVE-2019-10778CRITICAL9.8devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the ex...
CVE-2019-20362HIGH7.8In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of ...
CVE-2019-14820MEDIUM4.3It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterCons...
CVE-2019-20361CRITICAL9.8There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now