2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14822HIGH7.1A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method cal...
CVE-2019-14891MEDIUM5A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can res...
CVE-2019-14815HIGH7.8A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marve...
CVE-2019-10214MEDIUM5.9The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version...
CVE-2019-10174HIGH8.8A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allow...
CVE-2019-11287HIGH7.5Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x ver...
CVE-2019-11291MEDIUM4.8Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions p...
CVE-2019-18910MEDIUM6.8The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker t...
CVE-2019-18909HIGH8The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to ...
CVE-2019-16287MEDIUM6.8In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerabi...
CVE-2019-16286MEDIUM6.8An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by chang...
CVE-2019-16285MEDIUM4.6If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extra...
CVE-2019-15593MEDIUM6.5GitLab 12.2.3 contains a security vulnerability that allows a user to affect the availability of the service through a D...
CVE-2019-18622CRITICAL9.8An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection...
CVE-2019-13566CRITICAL9.8An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3...
CVE-2019-3654HIGH8.6Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l...
CVE-2019-19240MEDIUM5.3Embedthis GoAhead before 5.0.1 mishandles redirected HTTP requests with a large Host header. The GoAhead WebsRedirect us...
CVE-2019-16763MEDIUM6.1In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS a...
CVE-2019-9536MEDIUM6.8Apple iPhone 3GS bootrom malloc implementation returns a non-NULL pointer when unable to allocate memory, aka 'alloc8'. ...
CVE-2019-18610HIGH8.8An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 1...
CVE-2019-17446HIGH7.8An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operatio...
CVE-2019-17445MEDIUM5.5An issue was discovered in Eracent EDA, EPA, EPM, EUA, FLW, and SUM Agent through 10.2.26. The agent executable, when in...
CVE-2019-15652MEDIUM6.1The web interface for NSSLGlobal SatLink VSAT Modem Unit (VMU) devices before 18.1.0 doesn't properly sanitize input for...
CVE-2019-18976HIGH7.5An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If i...
CVE-2019-18790MEDIUM6.5An issue was discovered in channels/chan_sip.c in Sangoma Asterisk 13.x before 13.29.2, 16.x before 16.6.2, and 17.x bef...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now