2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-14054HIGH7.8Improper permissions in XBL_SEC region enable user to update XBL_SEC code and data and divert the RAM dump path to norma...
CVE-2019-14053HIGH7.1When attempting to create a new XFRM policy, a stack out-of-bounds read will occur if the user provides a template where...
CVE-2019-14043HIGH7.1Out of bound read in Fingerprint application due to requested data is being used without length check in Snapdragon Auto...
CVE-2019-14042HIGH7.1Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in...
CVE-2019-14039HIGH7.1Out of bound read in adm call back function due to incorrect boundary check for payload in command response in Snapdrago...
CVE-2019-14038HIGH7.1Buffer over-read in ADSP parse function due to lack of check for availability of sufficient data payload received in com...
CVE-2019-20804HIGH8.8Gila CMS before 1.11.6 allows CSRF with resultant XSS via the admin/themes URI, leading to compromise of the admin accou...
CVE-2019-17066HIGH7.8In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registri...
CVE-2019-19454HIGH7.5An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue ...
CVE-2019-20799HIGH7.5In Cherokee through 1.2.104, multiple memory corruption errors may be used by a remote attacker to destabilize the work ...
CVE-2019-20798HIGH8.4An XSS issue was discovered in handler_server_info.c in Cherokee through 1.2.104. The requested URL is improperly displa...
CVE-2019-20797HIGH7.5An issue was discovered in e6y prboom-plus 2.5.1.5. There is a buffer overflow in client and server code responsible for...
CVE-2019-20390HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was discovered in Subrion CMS 4.2.1 that allows a remote attacker to r...
CVE-2019-19721HIGH7.8An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows re...
CVE-2019-9682HIGH8.1Dahua devices with Build time before December 2019 use strong security login mode by default, but in order to be compati...
CVE-2019-15879HIGH7.4In FreeBSD 12.1-STABLE before r356908, 12.1-RELEASE before p5, 11.3-STABLE before r356908, and 11.3-RELEASE before p9, a...
CVE-2019-15878HIGH7.8In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local use...
CVE-2019-16112HIGH8.8TylerTech Eagle 2018.3.11 deserializes untrusted user input, resulting in remote code execution via a crafted Java objec...
CVE-2019-5500HIGH7.5Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthentic...
CVE-2019-19162HIGH7.8A use-after-free vulnerability in the TOBESOFT XPLATFORM versions 9.1 to 9.2.2 may lead to code execution on a system ru...
CVE-2019-14898HIGH7The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw ...
CVE-2019-10170HIGH7.2A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the ...
CVE-2019-10169HIGH7.2A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy...
CVE-2019-19164HIGH8.8dext5.ocx ActiveX Control in Dext5 Upload 5.0.0.112 and earlier versions contains a vulnerability that could allow remot...
CVE-2019-18872HIGH7.5Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable password...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now