2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7108 | HIGH | 7.5 | 3.2% | May 23, 2019 | Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bo... |
| CVE-2019-4078 | HIGH | 7.8 | 0.4% | May 23, 2019 | IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute co... |
| CVE-2019-10977 | HIGH | 7.5 | 3.5% | May 23, 2019 | In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send... |
| CVE-2019-12295 | HIGH | 7.5 | 3.8% | May 23, 2019 | In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed ... |
| CVE-2019-6807 | HIGH | 7.5 | 2.2% | May 22, 2019 | A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a... |
| CVE-2019-6806 | HIGH | 7.5 | 2.3% | May 22, 2019 | A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum,... |
| CVE-2019-6820 | HIGH | 8.2 | 1.2% | May 22, 2019 | A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device ... |
| CVE-2019-6819 | HIGH | 7.5 | 1.1% | May 22, 2019 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial... |
| CVE-2019-6812 | HIGH | 7.2 | 1.1% | May 22, 2019 | A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 ... |
| CVE-2019-8443 | HIGH | 8.1 | 2.6% | May 22, 2019 | The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0... |
| CVE-2019-8442 | HIGH | 7.5 | 59.8% | May 22, 2019 | The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4,... |
| CVE-2019-5627 | HIGH | 7.8 | 0.4% | May 22, 2019 | The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encod... |
| CVE-2019-5626 | HIGH | 7.8 | 0.4% | May 22, 2019 | The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This... |
| CVE-2019-5625 | HIGH | 7.1 | 0.4% | May 22, 2019 | The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear ... |
| CVE-2019-10132 | HIGH | 8.8 | 1.4% | May 22, 2019 | A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A m... |
| CVE-2019-11816 | HIGH | 7.2 | 3.3% | May 20, 2019 | Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authe... |
| CVE-2019-12239 | HIGH | 7.2 | 0.9% | May 20, 2019 | The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj... |
| CVE-2019-12211 | HIGH | 7.5 | 4.2% | May 20, 2019 | When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy... |
| CVE-2019-12086 | HIGH | 7.5 | 21.9% | May 17, 2019 | A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled... |
| CVE-2019-11057 | HIGH | 8.8 | 1.2% | May 17, 2019 | SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL comma... |
| CVE-2019-6781 | HIGH | 7.5 | 1.2% | May 17, 2019 | An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x befor... |
| CVE-2019-10139 | HIGH | 7.8 | 0.2% | May 17, 2019 | During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-s... |
| CVE-2019-0132 | HIGH | 7.5 | 2.0% | May 17, 2019 | Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially caus... |
| CVE-2019-0096 | HIGH | 8 | 0.5% | May 17, 2019 | Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may ... |
| CVE-2019-0090 | HIGH | 7.1 | 0.4% | May 17, 2019 | Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x,... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now