2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19197HIGH7.8IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escala...
CVE-2019-19191HIGH7.8Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlle...
CVE-2019-19033CRITICAL9.8Jalios JCMS 10 allows attackers to access any part of the website and the WebDAV server with administrative privileges v...
CVE-2019-19006CRITICAL9.8Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
CVE-2019-18890MEDIUM6.5A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected ...
CVE-2019-18886MEDIUM5.3An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due t...
CVE-2019-18349CRITICAL9.8HotkeyP through 4.9 r96 allows privilege escalation in the privilege function in Commands.cpp.
CVE-2019-16758HIGH7.5In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech...
CVE-2019-16406HIGH7.8Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual ma...
CVE-2019-16405HIGH7.2Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code...
CVE-2019-15511HIGH7.8An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due t...
CVE-2019-5072HIGH7.8An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Rout...
CVE-2019-5071HIGH7.8An exploitable command injection vulnerability exists in the /goform/WanParameterSetting functionality of Tenda AC9 Rout...
CVE-2019-10767HIGH7.5An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent...
CVE-2019-6693MEDIUM6.5Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacke...
CVE-2019-5509CRITICAL9.8ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerabil...
CVE-2019-5087HIGH8.8An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm bin...
CVE-2019-5086HIGH8.8An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm bin...
CVE-2019-17650HIGH7.8An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root pro...
CVE-2019-17272HIGH7.2All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully ex...
CVE-2019-2339HIGH7.8Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Au...
CVE-2019-2336MEDIUM5.5Subsequent use of the CBO listener may result in further memory corruption due to use after free issue. in Snapdragon Au...
CVE-2019-2335HIGH7.5While processing Attach Reject message, Valid exit condition is not met resulting into an infinite loop in Snapdragon Au...
CVE-2019-2329HIGH7.8Use after free issue in cleanup routine due to missing pointer sanitization for a failed start of a trusted application....
CVE-2019-2318MEDIUM5.5Non Secure Kernel can cause Trustzone to do an arbitrary memory read which will result into DOS in Snapdragon Auto, Snap...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now