2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14899HIGH7.4A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point,...
CVE-2019-18960CRITICAL9.8Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitab...
CVE-2019-18935CRITICAL9.8Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp...
CVE-2019-3667HIGH7.8DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allow...
CVE-2019-19720HIGH8.8Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file.
CVE-2019-19719MEDIUM6.1Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page.
CVE-2019-19709MEDIUM6.1MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitra...
CVE-2019-19708MEDIUM6.1The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve...
CVE-2019-19707HIGH7.5On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINE...
CVE-2019-5815HIGH7.5Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit ...
CVE-2019-19604HIGH7.8Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before ...
CVE-2019-14889HIGH8.8A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh S...
CVE-2019-14870MEDIUM5.4All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-...
CVE-2019-14861MEDIUM5.3All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly ...
CVE-2019-1490MEDIUM5.4A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request,...
CVE-2019-1489HIGH7.5An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle o...
CVE-2019-1488LOW3.3A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microso...
CVE-2019-1487MEDIUM6.5An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or lat...
CVE-2019-1486MEDIUM6.1A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected...
CVE-2019-1485HIGH7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip...
CVE-2019-1484HIGH7.8A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind...
CVE-2019-1483HIGH7.8An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e...
CVE-2019-1481MEDIUM4.3An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor...
CVE-2019-1480MEDIUM4.3An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor...
CVE-2019-1478HIGH7.8An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now