2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14054 | HIGH | 7.8 | 0.2% | Jun 2, 2020 | Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to norma... |
| CVE-2019-14053 | HIGH | 7.1 | 0.2% | Jun 2, 2020 | When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where... |
| CVE-2019-14043 | HIGH | 7.1 | 0.2% | Jun 2, 2020 | Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto... |
| CVE-2019-14042 | HIGH | 7.1 | 0.2% | Jun 2, 2020 | Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in... |
| CVE-2019-14039 | HIGH | 7.1 | 0.2% | Jun 2, 2020 | Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdrago... |
| CVE-2019-14038 | HIGH | 7.1 | 0.2% | Jun 2, 2020 | Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in com... |
| CVE-2019-20804 | HIGH | 8.8 | 1.1% | May 21, 2020 | Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin accou... |
| CVE-2019-17066 | HIGH | 7.8 | 0.5% | May 18, 2020 | In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registri... |
| CVE-2019-19454 | HIGH | 7.5 | 1.6% | May 18, 2020 | An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue ... |
| CVE-2019-20799 | HIGH | 7.5 | 2.4% | May 18, 2020 | In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work ... |
| CVE-2019-20798 | HIGH | 8.4 | 1.7% | May 18, 2020 | An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displa... |
| CVE-2019-20797 | HIGH | 7.5 | 2.7% | May 18, 2020 | An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for... |
| CVE-2019-20390 | HIGH | 8.1 | 0.7% | May 15, 2020 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to r... |
| CVE-2019-19721 | HIGH | 7.8 | 1.9% | May 15, 2020 | An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows re... |
| CVE-2019-9682 | HIGH | 8.1 | 0.9% | May 13, 2020 | Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compati... |
| CVE-2019-15879 | HIGH | 7.4 | 0.7% | May 13, 2020 | In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a... |
| CVE-2019-15878 | HIGH | 7.8 | 0.3% | May 13, 2020 | In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use... |
| CVE-2019-16112 | HIGH | 8.8 | 11.4% | May 13, 2020 | TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java objec... |
| CVE-2019-5500 | HIGH | 7.5 | 1.8% | May 11, 2020 | Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthentic... |
| CVE-2019-19162 | HIGH | 7.8 | 1.2% | May 11, 2020 | A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system ru... |
| CVE-2019-14898 | HIGH | 7 | 0.4% | May 8, 2020 | The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw ... |
| CVE-2019-10170 | HIGH | 7.2 | 1.2% | May 8, 2020 | A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the ... |
| CVE-2019-10169 | HIGH | 7.2 | 1.3% | May 8, 2020 | A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy... |
| CVE-2019-19164 | HIGH | 8.8 | 0.8% | May 7, 2020 | dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remot... |
| CVE-2019-18872 | HIGH | 7.5 | 0.9% | May 7, 2020 | Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable password... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now