2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-18250 | CRITICAL | 9.8 | 1.7% | Nov 26, 2019 | In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable... |
| CVE-2019-18241 | MEDIUM | 6.5 | 0.3% | Nov 26, 2019 | In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, th... |
| CVE-2019-15595 | HIGH | 8.8 | 1.7% | Nov 26, 2019 | A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to ru... |
| CVE-2019-11290 | HIGH | 7.5 | 1.3% | Nov 26, 2019 | Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query pa... |
| CVE-2019-10771 | MEDIUM | 6.1 | 0.7% | Nov 25, 2019 | Characters in the GET url path are not properly escaped and can be reflected in the server response. |
| CVE-2019-17632 | MEDIUM | 6.1 | 1.9% | Nov 25, 2019 | In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled ... |
| CVE-2019-15629 | HIGH | 7.5 | 2.9% | Nov 25, 2019 | Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that coul... |
| CVE-2019-5826 | MEDIUM | 6.5 | 1.0% | Nov 25, 2019 | Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the ren... |
| CVE-2019-5825 | MEDIUM | 6.5 | 55.9% | Nov 25, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi... |
| CVE-2019-19244 | HIGH | 7.5 | 3.3% | Nov 25, 2019 | sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and a... |
| CVE-2019-19252 | HIGH | 7.8 | 0.4% | Nov 25, 2019 | vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices... |
| CVE-2019-16765 | HIGH | 7.8 | 4.7% | Nov 25, 2019 | If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the ... |
| CVE-2019-4406 | MEDIUM | 4.4 | 0.3% | Nov 25, 2019 | IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing i... |
| CVE-2019-19250 | CRITICAL | 9.8 | 1.0% | Nov 25, 2019 | OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js. |
| CVE-2019-19249 | CRITICAL | 9.8 | 1.2% | Nov 25, 2019 | Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations. |
| CVE-2019-19246 | HIGH | 7.5 | 2.9% | Nov 25, 2019 | Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_ma... |
| CVE-2019-18374 | CRITICAL | 9.8 | 1.7% | Nov 25, 2019 | Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypa... |
| CVE-2019-16764 | MEDIUM | 5.5 | 1.1% | Nov 25, 2019 | The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.Authorizat... |
| CVE-2019-17406 | MEDIUM | 5.3 | 1.1% | Nov 25, 2019 | Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743 |
| CVE-2019-15684 | MEDIUM | 4.3 | 0.4% | Nov 25, 2019 | Kaspersky Protection extension for web browser Google Chrome prior to 30.112.62.0 was vulnerable to unauthorized access ... |
| CVE-2019-14825 | LOW | 2.7 | 0.6% | Nov 25, 2019 | A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credent... |
| CVE-2019-10224 | MEDIUM | 4.6 | 0.4% | Nov 25, 2019 | A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and ds... |
| CVE-2019-10217 | MEDIUM | 6.5 | 1.6% | Nov 25, 2019 | A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. ... |
| CVE-2019-5881 | HIGH | 8.1 | 1.0% | Nov 25, 2019 | Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially... |
| CVE-2019-5880 | HIGH | 7.4 | 0.9% | Nov 25, 2019 | Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now