2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13730HIGH8.8Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea...
CVE-2019-13729HIGH8.8Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea...
CVE-2019-13728HIGH8.8Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploi...
CVE-2019-13727HIGH8.8Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass...
CVE-2019-13726HIGH8.8Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrar...
CVE-2019-13725HIGH8.8Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code v...
CVE-2019-5843HIGH8.8Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potential...
CVE-2019-5841HIGH8.8Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentiall...
CVE-2019-17270CRITICAL9.8Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi...
CVE-2019-13672MEDIUM6.5Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof t...
CVE-2019-19703MEDIUM6.1In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
CVE-2019-19702HIGH7.5The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processin...
CVE-2019-6192MEDIUM4.4A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a ...
CVE-2019-6183HIGH7.5A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to ...
CVE-2019-4663MEDIUM5.4IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2019-4521CRITICAL9.8Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could ...
CVE-2019-4244CRITICAL9.1IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestri...
CVE-2019-4095MEDIUM4.3IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ...
CVE-2019-19251MEDIUM5.3The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without ...
CVE-2019-19698MEDIUM6.5marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.
CVE-2019-4621CRITICAL9.8IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account tha...
CVE-2019-4612HIGH8.8IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of th...
CVE-2019-4611MEDIUM5.4IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2019-4428MEDIUM5.4IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerab...
CVE-2019-19230CRITICAL9.8An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now