2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18250CRITICAL9.8In all versions of ABB Power Generation Information Manager (PGIM) and Plant Connect, the affected product is vulnerable...
CVE-2019-18241MEDIUM6.5In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, th...
CVE-2019-15595HIGH8.8A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to ru...
CVE-2019-11290HIGH7.5Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query pa...
CVE-2019-10771MEDIUM6.1Characters in the GET url path are not properly escaped and can be reflected in the server response.
CVE-2019-17632MEDIUM6.1In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled ...
CVE-2019-15629HIGH7.5Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that coul...
CVE-2019-5826MEDIUM6.5Use after free in IndexedDB in Google Chrome prior to 73.0.3683.86 allowed a remote attacker who had compromised the ren...
CVE-2019-5825MEDIUM6.5Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi...
CVE-2019-19244HIGH7.5sqlite3Select in select.c in SQLite 3.30.1 allows a crash if a sub-select uses both DISTINCT and window functions, and a...
CVE-2019-19252HIGH7.8vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through 5.3.13 does not prevent write access to vcsu devices...
CVE-2019-16765HIGH7.8If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the ...
CVE-2019-4406MEDIUM4.4IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing i...
CVE-2019-19250CRITICAL9.8OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.
CVE-2019-19249CRITICAL9.8Controllers/InvitationsController.cs in QueryTree before 3.0.99-beta mishandles invitations.
CVE-2019-19246HIGH7.5Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_ma...
CVE-2019-18374CRITICAL9.8Symantec Critical System Protection (CSP), versions 8.0, 8.0 HF1 & 8.0 MP1, may be susceptible to an authentication bypa...
CVE-2019-16764MEDIUM5.5The use of `String.to_atom/1` in PowAssent is susceptible to denial of service attacks. In `PowAssent.Phoenix.Authorizat...
CVE-2019-17406MEDIUM5.3Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
CVE-2019-15684MEDIUM4.3Kaspersky Protection extension for web browser Google Chrome prior to 30.112.62.0 was vulnerable to unauthorized access ...
CVE-2019-14825LOW2.7A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credent...
CVE-2019-10224MEDIUM4.6A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and ds...
CVE-2019-10217MEDIUM6.5A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. ...
CVE-2019-5881HIGH8.1Out of bounds read in SwiftShader in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to obtain potentially...
CVE-2019-5880HIGH7.4Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now