2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19286HIGH7.2A vulnerability has been identified in XHQ (All Versions < 6.1). The web interface could allow SQL injection attacks if ...
CVE-2019-19878HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical d...
CVE-2019-19873HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get information from the A...
CVE-2019-19869HIGH7.5An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. PVs could be changed (unencrypted) by usin...
CVE-2019-20925HIGH7.5An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause...
CVE-2019-14586HIGH8Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, in...
CVE-2019-14575HIGH7.8Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation...
CVE-2019-14563HIGH7.8Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local acc...
CVE-2019-14559HIGH7.5Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service vi...
CVE-2019-12412HIGH7.5A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remot...
CVE-2019-17566HIGH7.5Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attri...
CVE-2019-11121HIGH7.8Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an au...
CVE-2019-7357HIGH8.8Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
CVE-2019-8854HIGH7.5A user privacy issue was addressed by removing the broadcast MAC address. This issue is fixed in macOS Catalina 10.15, w...
CVE-2019-8852HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Se...
CVE-2019-8848HIGH7.8This issue was addressed with improved checks. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9,...
CVE-2019-8847HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.2, Se...
CVE-2019-8846HIGH8.8A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windo...
CVE-2019-8851HIGH7.5A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.2, Security Upda...
CVE-2019-8844HIGH8.8Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchO...
CVE-2019-8841HIGH7.8An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadO...
CVE-2019-8840HIGH8.8An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with unt...
CVE-2019-8838HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, ...
CVE-2019-8837HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.2, Security Update 2...
CVE-2019-8836HIGH7.8A memory corruption issue was addressed with improved memory handling. This issue is fixed in watchOS 6.1.2, iOS 13.3.1 ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now