2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-7108HIGH7.5Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bo...
CVE-2019-4078HIGH7.8IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute co...
CVE-2019-10977HIGH7.5In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send...
CVE-2019-12295HIGH7.5In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed ...
CVE-2019-6807HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a...
CVE-2019-6806HIGH7.5A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum,...
CVE-2019-6820HIGH8.2A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device ...
CVE-2019-6819HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial...
CVE-2019-6812HIGH7.2A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 ...
CVE-2019-8443HIGH8.1The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0...
CVE-2019-8442HIGH7.5The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4,...
CVE-2019-5627HIGH7.8The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encod...
CVE-2019-5626HIGH7.8The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This...
CVE-2019-5625HIGH7.1The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear ...
CVE-2019-10132HIGH8.8A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A m...
CVE-2019-11816HIGH7.2Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authe...
CVE-2019-12239HIGH7.2The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj...
CVE-2019-12211HIGH7.5When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy...
CVE-2019-12086HIGH7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled...
CVE-2019-11057HIGH8.8SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL comma...
CVE-2019-6781HIGH7.5An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x befor...
CVE-2019-10139HIGH7.8During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-s...
CVE-2019-0132HIGH7.5Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially caus...
CVE-2019-0096HIGH8Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may ...
CVE-2019-0090HIGH7.1Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x,...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now