2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6189HIGH7.8A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow ...
CVE-2019-6187MEDIUM6.5A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative...
CVE-2019-6186HIGH8.8A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow ...
CVE-2019-6184HIGH7.8A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow lo...
CVE-2019-6176HIGH7.5A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.
CVE-2019-19126LOW3.3On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC envir...
CVE-2019-12421HIGH8.8When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi versions 1.0.0 to 1.9.2, NiF...
CVE-2019-10083MEDIUM5.3When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of i...
CVE-2019-10080MEDIUM6.5The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially ...
CVE-2019-10768HIGH7.5In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototy...
CVE-2019-10766CRITICAL9.8Pixie versions 1.0.x before 1.0.3, and 2.0.x before 2.0.2 allow SQL Injection in the limit() function due to improper sa...
CVE-2019-11289HIGH8.6Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated mal...
CVE-2019-18934HIGH7.3Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiv...
CVE-2019-16861HIGH7.3Code42 server through 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative attack...
CVE-2019-16860HIGH7.3Code42 app through version 7.0.2 for Windows has an Untrusted Search Path. In certain situations, a non-administrative a...
CVE-2019-12422HIGH7.5Apache Shiro before 1.4.2, when using the default "remember me" configuration, cookies could be susceptible to a padding...
CVE-2019-19117HIGH8.8/usr/lib/lua/luci/controller/admin/autoupgrade.lua on PHICOMM K2(PSG1218) V22.5.9.163 devices allows remote authenticate...
CVE-2019-10764HIGH7.4In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the ...
CVE-2019-18373MEDIUM5.6Norton App Lock, prior to 1.4.0.503, may be susceptible to a bypass exploit. In this type of circumstance, the exploit c...
CVE-2019-17085MEDIUM6.5XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.0...
CVE-2019-15054MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Mailbird before 2.7.5.0 r allow remote attackers to execute arbit...
CVE-2019-12409CRITICAL9.8The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration opt...
CVE-2019-12403Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-10070MEDIUM6.1Apache Atlas versions 0.8.3 and 1.1.0 were found vulnerable to Stored Cross-Site Scripting in the search functionality
CVE-2019-18215HIGH7.8An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerabilit...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now