2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16772MEDIUM6.1The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly m...
CVE-2019-9464MEDIUM5.5In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is ...
CVE-2019-2232HIGH7.5In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead t...
CVE-2019-2231MEDIUM4.4In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead ...
CVE-2019-2230HIGH7.5In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use af...
CVE-2019-2229MEDIUM5.5In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. Thi...
CVE-2019-2228MEDIUM5.5In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo...
CVE-2019-2227MEDIUM6.5In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote inf...
CVE-2019-2226MEDIUM5.5In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could le...
CVE-2019-2225HIGH8.8When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the us...
CVE-2019-2224Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15140. Reason: This candidate is a duplicate of ...
CVE-2019-2223HIGH7.8In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2019-2222HIGH7.8n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check...
CVE-2019-2221HIGH7.8In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements d...
CVE-2019-2220MEDIUM5.5In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling ...
CVE-2019-2219MEDIUM4.7In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from ...
CVE-2019-2218HIGH7.8In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing...
CVE-2019-2217HIGH7.8In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to lo...
CVE-2019-10769CRITICAL9.8safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of thi...
CVE-2019-18575HIGH7.1Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticate...
CVE-2019-11293MEDIUM6.5Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials w...
CVE-2019-16771MEDIUM6.5Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote a...
CVE-2019-1551MEDIUM5.3There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC a...
CVE-2019-18672HIGH7.5Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a ...
CVE-2019-18671CRITICAL9.8Insufficient checks in the USB packet handling of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow out...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now