2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-6173MEDIUM6.5A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version ...
CVE-2019-19412MEDIUM4.6Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile ...
CVE-2019-20835MEDIUM4.3An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling.
CVE-2019-20832MEDIUM4.3An issue was discovered in Foxit PhantomPDF before 8.3.10. It has homograph mishandling.
CVE-2019-16385MEDIUM6.1Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer reque...
CVE-2019-16384MEDIUM6.5Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables file...
CVE-2019-16150MEDIUM5.5Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClie...
CVE-2019-20812MEDIUM5.5An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet...
CVE-2019-20811MEDIUM5.5An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in ne...
CVE-2019-20810MEDIUM5.5go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for ...
CVE-2019-11843MEDIUM6.1The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using ext...
CVE-2019-14067MEDIUM5.5Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing s...
CVE-2019-15709MEDIUM6.5An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin consol...
CVE-2019-20805MEDIUM5.5p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment.
CVE-2019-20807MEDIUM5.3In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting in...
CVE-2019-20806MEDIUM4.4An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in ...
CVE-2019-20803MEDIUM6.1Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_prev...
CVE-2019-11048MEDIUM5.3In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supply...
CVE-2019-19456MEDIUM6.1A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza ...
CVE-2019-7246MEDIUM6.7An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. T...
CVE-2019-20802MEDIUM6.1An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server im...
CVE-2019-20801MEDIUM5.3An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al...
CVE-2019-20389MEDIUM6.1An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can i...
CVE-2019-17572MEDIUM5.3In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topi...
CVE-2019-13023MEDIUM6.5An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now