2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5788HIGH8.8An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo...
CVE-2019-5787HIGH8.8Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially ex...
CVE-2019-7061HIGH7.5Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7108HIGH7.5Adobe Flash Player versions 32.0.0.156 and earlier, 32.0.0.156 and earlier, and 32.0.0.156 and earlier have an out-of-bo...
CVE-2019-4078HIGH7.8IBM WebSphere MQ 8.0.0.0 through 8.0.0.9 and 9.0.0.0 through 9.1.1 could allow a local non privileged user to execute co...
CVE-2019-10977HIGH7.5In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send...
CVE-2019-12295HIGH7.5In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed ...
CVE-2019-6807HIGH7.5A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, a...
CVE-2019-6806HIGH7.5A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum,...
CVE-2019-6820HIGH8.2A CWE-306: Missing Authentication for Critical Function vulnerability exists which could cause a modification of device ...
CVE-2019-6819HIGH7.5A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists which could cause a possible Denial...
CVE-2019-6812HIGH7.2A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware versions prior to V1.7 IR 19 ...
CVE-2019-8443HIGH8.1The ViewUpgrades resource in Jira before version 7.13.4, from version 8.0.0 before version 8.0.4, and from version 8.1.0...
CVE-2019-8442HIGH7.5The CachingResourceDownloadRewriteRule class in Jira before version 7.13.4, and from version 8.0.0 before version 8.0.4,...
CVE-2019-5627HIGH7.8The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encod...
CVE-2019-5626HIGH7.8The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This...
CVE-2019-5625HIGH7.1The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear ...
CVE-2019-10132HIGH8.8A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A m...
CVE-2019-11816HIGH7.2Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authe...
CVE-2019-12239HIGH7.2The WP Booking System plugin 1.5.1 for WordPress has no CSRF protection, which allows attackers to reach certain SQL inj...
CVE-2019-12211HIGH7.5When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy...
CVE-2019-12086HIGH7.5A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled...
CVE-2019-11057HIGH8.8SQL injection vulnerability in Vtiger CRM before 7.1.0 hotfix3 allows authenticated users to execute arbitrary SQL comma...
CVE-2019-6781HIGH7.5An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x befor...
CVE-2019-10139HIGH7.8During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now