2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14899 | HIGH | 7.4 | 0.8% | Dec 11, 2019 | A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point,... |
| CVE-2019-18960 | CRITICAL | 9.8 | 3.3% | Dec 11, 2019 | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitab... |
| CVE-2019-18935 | CRITICAL | 9.8 | 99.7% | Dec 11, 2019 | Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp... |
| CVE-2019-3667 | HIGH | 7.8 | 0.3% | Dec 11, 2019 | DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allow... |
| CVE-2019-19720 | HIGH | 8.8 | 1.2% | Dec 11, 2019 | Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. |
| CVE-2019-19719 | MEDIUM | 6.1 | 22.0% | Dec 11, 2019 | Tableau Server 10.3 through 2019.4 on Windows and Linux allows XSS via the embeddedAuthRedirect page. |
| CVE-2019-19709 | MEDIUM | 6.1 | 1.6% | Dec 11, 2019 | MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitra... |
| CVE-2019-19708 | MEDIUM | 6.1 | 0.7% | Dec 11, 2019 | The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve... |
| CVE-2019-19707 | HIGH | 7.5 | 1.2% | Dec 11, 2019 | On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINE... |
| CVE-2019-5815 | HIGH | 7.5 | 1.7% | Dec 11, 2019 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit ... |
| CVE-2019-19604 | HIGH | 7.8 | 3.7% | Dec 11, 2019 | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before ... |
| CVE-2019-14889 | HIGH | 8.8 | 3.2% | Dec 10, 2019 | A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh S... |
| CVE-2019-14870 | MEDIUM | 5.4 | 2.8% | Dec 10, 2019 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-... |
| CVE-2019-14861 | MEDIUM | 5.3 | 2.3% | Dec 10, 2019 | All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly ... |
| CVE-2019-1490 | MEDIUM | 5.4 | 1.4% | Dec 10, 2019 | A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request,... |
| CVE-2019-1489 | HIGH | 7.5 | 7.7% | Dec 10, 2019 | An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle o... |
| CVE-2019-1488 | LOW | 3.3 | 0.8% | Dec 10, 2019 | A security feature bypass vulnerability exists when Microsoft Defender improperly handles specific buffers, aka 'Microso... |
| CVE-2019-1487 | MEDIUM | 6.5 | 4.0% | Dec 10, 2019 | An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or lat... |
| CVE-2019-1486 | MEDIUM | 6.1 | 1.5% | Dec 10, 2019 | A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected... |
| CVE-2019-1485 | HIGH | 7.5 | 7.7% | Dec 10, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip... |
| CVE-2019-1484 | HIGH | 7.8 | 8.9% | Dec 10, 2019 | A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind... |
| CVE-2019-1483 | HIGH | 7.8 | 1.8% | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e... |
| CVE-2019-1481 | MEDIUM | 4.3 | 12.3% | Dec 10, 2019 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor... |
| CVE-2019-1480 | MEDIUM | 4.3 | 5.4% | Dec 10, 2019 | An information disclosure vulnerability exists in Windows Media Player when it fails to properly handle objects in memor... |
| CVE-2019-1478 | HIGH | 7.8 | 0.8% | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now