2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-8525MEDIUM6.7A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Mojave 10.14.5, Sec...
CVE-2019-7291MEDIUM6.5A denial of service issue was addressed with improved memory handling. This issue is fixed in AirPort Base Station Firmw...
CVE-2019-14718MEDIUM6.7Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol...
CVE-2019-14716MEDIUM6.6Verifone VerixV Pinpad Payment Terminals with QT000530 have an undocumented physical access mode (aka VerixV shell.out).
CVE-2019-14715MEDIUM6.8Verifone Pinpad Payment Terminals allow undocumented physical access to the system via an SBI bootloader memory write op...
CVE-2019-14713MEDIUM5.5Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.
CVE-2019-16128MEDIUM6.8Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
CVE-2019-16129MEDIUM6.8Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
CVE-2019-13633MEDIUM6.1Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-...
CVE-2019-12305MEDIUM6.5In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access...
CVE-2019-18796MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinit...
CVE-2019-18795MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a c...
CVE-2019-18794MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a craft...
CVE-2019-4552MEDIUM6.1IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attack...
CVE-2019-4325MEDIUM5.3"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
CVE-2019-4725MEDIUM6.1IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2019-14558MEDIUM5.7Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(...
CVE-2019-14556MEDIUM4.4Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor ...
CVE-2019-19393MEDIUM6.1The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on...
CVE-2019-20903MEDIUM5.4The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitra...
CVE-2019-20921MEDIUM6.1bootstrap-select before 1.13.6 allows Cross-Site Scripting (XSS). It does not escape title values in OPTION elements. Th...
CVE-2019-18991MEDIUM5.4A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA d...
CVE-2019-18990MEDIUM5.4A partial authentication bypass vulnerability exists on Realtek RTL8812AR 1.21WW, RTL8196D 1.0.0, RTL8192ER 2.10, and RT...
CVE-2019-18989MEDIUM5.4A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending ...
CVE-2019-17098MEDIUM6.5Use of hard-coded cryptographic key vulnerability in August Connect Wi-Fi Bridge App, Connect Firmware allows an attacke...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now