2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6173 | MEDIUM | 6.5 | 0.3% | Jun 9, 2020 | A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version ... |
| CVE-2019-19412 | MEDIUM | 4.6 | 0.2% | Jun 8, 2020 | Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile ... |
| CVE-2019-20835 | MEDIUM | 4.3 | 1.0% | Jun 4, 2020 | An issue was discovered in Foxit Reader and PhantomPDF before 9.5. It has homograph mishandling. |
| CVE-2019-20832 | MEDIUM | 4.3 | 1.0% | Jun 4, 2020 | An issue was discovered in Foxit PhantomPDF before 8.3.10. It has homograph mishandling. |
| CVE-2019-16385 | MEDIUM | 6.1 | 0.8% | Jun 4, 2020 | Cybele Thinfinity VirtualUI 2.5.17.2 allows HTTP response splitting via the mimetype parameter within a PDF viewer reque... |
| CVE-2019-16384 | MEDIUM | 6.5 | 1.1% | Jun 4, 2020 | Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables file... |
| CVE-2019-16150 | MEDIUM | 5.5 | 1.0% | Jun 4, 2020 | Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClie... |
| CVE-2019-20812 | MEDIUM | 5.5 | 0.5% | Jun 3, 2020 | An issue was discovered in the Linux kernel before 5.4.7. The prb_calc_retire_blk_tmo() function in net/packet/af_packet... |
| CVE-2019-20811 | MEDIUM | 5.5 | 0.4% | Jun 3, 2020 | An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in ne... |
| CVE-2019-20810 | MEDIUM | 5.5 | 0.5% | Jun 3, 2020 | go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for ... |
| CVE-2019-11843 | MEDIUM | 6.1 | 1.8% | Jun 2, 2020 | The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using ext... |
| CVE-2019-14067 | MEDIUM | 5.5 | 0.2% | Jun 2, 2020 | Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing s... |
| CVE-2019-15709 | MEDIUM | 6.5 | 1.3% | Jun 1, 2020 | An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin consol... |
| CVE-2019-20805 | MEDIUM | 5.5 | 0.7% | Jun 1, 2020 | p_lx_elf.cpp in UPX before 3.96 has an integer overflow during unpacking via crafted values in a PT_DYNAMIC segment. |
| CVE-2019-20807 | MEDIUM | 5.3 | 0.5% | May 28, 2020 | In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting in... |
| CVE-2019-20806 | MEDIUM | 4.4 | 0.4% | May 27, 2020 | An issue was discovered in the Linux kernel before 5.2. There is a NULL pointer dereference in tw5864_handle_frame() in ... |
| CVE-2019-20803 | MEDIUM | 6.1 | 1.8% | May 21, 2020 | Gila CMS before 1.11.6 has reflected XSS via the admin/content/postcategory id parameter, which is mishandled for g_prev... |
| CVE-2019-11048 | MEDIUM | 5.3 | 6.3% | May 20, 2020 | In PHP versions 7.2.x below 7.2.31, 7.3.x below 7.3.18 and 7.4.x below 7.4.6, when HTTP file uploads are allowed, supply... |
| CVE-2019-19456 | MEDIUM | 6.1 | 1.0% | May 18, 2020 | A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza ... |
| CVE-2019-7246 | MEDIUM | 6.7 | 0.4% | May 18, 2020 | An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. T... |
| CVE-2019-20802 | MEDIUM | 6.1 | 0.7% | May 18, 2020 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server im... |
| CVE-2019-20801 | MEDIUM | 5.3 | 1.0% | May 18, 2020 | An issue was discovered in the Readdle Documents app before 6.9.7 for iOS. The application's file-transfer web server al... |
| CVE-2019-20389 | MEDIUM | 6.1 | 0.9% | May 15, 2020 | An XSS issue was identified on the Subrion CMS 4.2.1 /panel/configuration/general settings page. A remote attacker can i... |
| CVE-2019-17572 | MEDIUM | 5.3 | 3.0% | May 14, 2020 | In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topi... |
| CVE-2019-13023 | MEDIUM | 6.5 | 0.8% | May 14, 2020 | An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RAD... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now