2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5225HIGH7.8P30, Mate 20, P30 Pro smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21), versions ea...
CVE-2019-5224MEDIUM5.5P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R1P21) have an out of bounds read vulnerability. ...
CVE-2019-5218HIGH8.8There is an insufficient authentication vulnerability in Huawei Band 2 and Honor Band 3. The band does not sufficiently ...
CVE-2019-5212MEDIUM5.5There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to cer...
CVE-2019-5211MEDIUM5.7The Huawei Share function of P20 phones with versions earlier than Emily-L29C 9.1.0.311 has an improper file management ...
CVE-2019-5210HIGH7.8Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(...
CVE-2019-5226MEDIUM5.5P30, P30 Pro, Mate 20 smartphones with software of versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1), versions ear...
CVE-2019-18922HIGH7.5A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] al...
CVE-2019-16767HIGH7.2The admin sys mode is now conditional and dedicated for the special case. By default, since ezmaster@5.2.11 no instance ...
CVE-2019-19378HIGH7.8In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image can lead to slab-out-of-bounds write access in ind...
CVE-2019-16766HIGH8.8When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into t...
CVE-2019-19391CRITICAL9.1In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue th...
CVE-2019-19377HIGH7.8In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and unmounting can le...
CVE-2019-14901CRITICAL9.8A heap overflow flaw was found in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip dri...
CVE-2019-14897CRITICAL9.8A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An atta...
CVE-2019-14895CRITICAL9.8A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell ...
CVE-2019-14865MEDIUM5.9A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pres...
CVE-2019-19388MEDIUM6.1A cross-site scripting (XSS) vulnerability in app/dialplans/dialplan_detail_edit.php in FusionPBX 4.4.1 allows remote at...
CVE-2019-19387MEDIUM6.1A cross-site scripting (XSS) vulnerability in app/fifo_list/fifo_interactive.php in FusionPBX 4.4.1 allows remote attack...
CVE-2019-19386MEDIUM6.1A cross-site scripting (XSS) vulnerability in app/voicemail_greetings/voicemail_greeting_edit.php in FusionPBX 4.4.1 all...
CVE-2019-19385MEDIUM6.1A cross-site scripting (XSS) vulnerability in app/dialplans/dialplans.php in FusionPBX 4.4.1 allows remote attackers to ...
CVE-2019-19384MEDIUM6.1A cross-site scripting (XSS) vulnerability in app/fax/fax_log_view.php in FusionPBX 4.4.1 allows remote attackers to inj...
CVE-2019-19379MEDIUM5.3In app/Controller/TagsController.php in MISP 2.4.118, users can bypass intended restrictions on tagging data.
CVE-2019-19376MEDIUM6.5In Octopus Deploy before 2019.10.6, an authenticated user with TeamEdit permission could send a malformed Team API reque...
CVE-2019-19375MEDIUM5.3In Octopus Deploy before 2019.10.7, in a configuration where SSL offloading is enabled, the CSRF cookie was sometimes se...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now