2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13730 | HIGH | 8.8 | 1.9% | Dec 10, 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-13729 | HIGH | 8.8 | 1.5% | Dec 10, 2019 | Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-13728 | HIGH | 8.8 | 1.6% | Dec 10, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploi... |
| CVE-2019-13727 | HIGH | 8.8 | 1.4% | Dec 10, 2019 | Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass... |
| CVE-2019-13726 | HIGH | 8.8 | 2.2% | Dec 10, 2019 | Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrar... |
| CVE-2019-13725 | HIGH | 8.8 | 2.0% | Dec 10, 2019 | Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code v... |
| CVE-2019-5843 | HIGH | 8.8 | 0.8% | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potential... |
| CVE-2019-5841 | HIGH | 8.8 | 0.8% | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentiall... |
| CVE-2019-17270 | CRITICAL | 9.8 | 58.9% | Dec 10, 2019 | Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user vi... |
| CVE-2019-13672 | MEDIUM | 6.5 | 0.6% | Dec 10, 2019 | Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof t... |
| CVE-2019-19703 | MEDIUM | 6.1 | 0.6% | Dec 10, 2019 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. |
| CVE-2019-19702 | HIGH | 7.5 | 1.5% | Dec 10, 2019 | The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processin... |
| CVE-2019-6192 | MEDIUM | 4.4 | 1.7% | Dec 10, 2019 | A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a ... |
| CVE-2019-6183 | HIGH | 7.5 | 1.9% | Dec 10, 2019 | A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to ... |
| CVE-2019-4663 | MEDIUM | 5.4 | 0.7% | Dec 10, 2019 | IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2019-4521 | CRITICAL | 9.8 | 2.6% | Dec 10, 2019 | Platform System Manager in IBM Cloud Pak System 2.3 is potentially vulnerable to CVS Injection. A remote attacker could ... |
| CVE-2019-4244 | CRITICAL | 9.1 | 2.1% | Dec 10, 2019 | IBM SmartCloud Analytics 1.3.1 through 1.3.5 could allow a remote attacker to gain unauthorized information and unrestri... |
| CVE-2019-4095 | MEDIUM | 4.3 | 0.4% | Dec 10, 2019 | IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ... |
| CVE-2019-19251 | MEDIUM | 5.3 | 0.7% | Dec 10, 2019 | The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without ... |
| CVE-2019-19698 | MEDIUM | 6.5 | 1.2% | Dec 10, 2019 | marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c. |
| CVE-2019-4621 | CRITICAL | 9.8 | 1.6% | Dec 9, 2019 | IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account tha... |
| CVE-2019-4612 | HIGH | 8.8 | 1.0% | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of th... |
| CVE-2019-4611 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2019-4428 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2019-19230 | CRITICAL | 9.8 | 3.8% | Dec 9, 2019 | An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now