2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-0560 | — | — | 8.7% | Jan 8, 2019 | An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, ak... |
| CVE-2019-0559 | — | — | 6.8% | Jan 8, 2019 | An information disclosure vulnerability exists when Microsoft Outlook improperly handles certain types of messages, aka ... |
| CVE-2019-0555 | — | — | 2.4% | Jan 8, 2019 | An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape... |
| CVE-2019-0554 | — | — | 1.8% | Jan 8, 2019 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2019-0553 | — | — | 1.8% | Jan 8, 2019 | An information disclosure vulnerability exists when Windows Subsystem for Linux improperly handles objects in memory, ak... |
| CVE-2019-0552 | — | — | 2.5% | Jan 8, 2019 | An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability." ... |
| CVE-2019-0551 | — | — | 4.5% | Jan 8, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from... |
| CVE-2019-0550 | — | — | 4.5% | Jan 8, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from... |
| CVE-2019-0549 | — | — | 1.8% | Jan 8, 2019 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2019-0548 | — | — | 8.2% | Jan 8, 2019 | A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of ... |
| CVE-2019-0547 | — | — | 71.4% | Jan 8, 2019 | A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon... |
| CVE-2019-0546 | — | — | 16.1% | Jan 8, 2019 | A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinat... |
| CVE-2019-0545 | — | — | 9.6% | Jan 8, 2019 | An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resou... |
| CVE-2019-0539 | — | — | 82.9% | Jan 8, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi... |
| CVE-2019-0537 | — | — | 7.6% | Jan 8, 2019 | An information disclosure vulnerability exists when Visual Studio improperly discloses arbitrary file contents if the vi... |
| CVE-2019-0536 | — | — | 1.8% | Jan 8, 2019 | An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Window... |
| CVE-2019-0249 | — | — | 1.7% | Jan 8, 2019 | Under certain conditions SAP Landscape Management (VCM 3.0) allows an attacker to access information which would otherwi... |
| CVE-2019-0247 | — | — | 1.3% | Jan 8, 2019 | SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. A... |
| CVE-2019-0246 | — | — | 2.7% | Jan 8, 2019 | SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require ... |
| CVE-2019-0245 | — | — | 0.8% | Jan 8, 2019 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficient... |
| CVE-2019-0244 | — | — | 0.8% | Jan 8, 2019 | SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficient... |
| CVE-2019-0243 | — | — | 1.7% | Jan 8, 2019 | Under some circumstances, masterdata maintenance in SAP BW/4HANA (fixed in DW4CORE version 1.0 (SP08)) does not perform ... |
| CVE-2019-0241 | — | — | 2.0% | Jan 8, 2019 | SAP Work and Inventory Manager (Agentry_SDK , before 7.0, 7.1) allows an attacker to prevent legitimate users from acces... |
| CVE-2019-0240 | — | — | 2.0% | Jan 8, 2019 | SAP Business Objects Mobile for Android (before 6.3.5) application allows an attacker to provide malicious input in the ... |
| CVE-2019-0238 | — | — | 1.0% | Jan 8, 2019 | SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now