2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-2199MEDIUM6.7In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to loc...
CVE-2019-2198MEDIUM5.5In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure w...
CVE-2019-2197MEDIUM5.5In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure defaul...
CVE-2019-2196MEDIUM5.5In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additiona...
CVE-2019-2195HIGH7.8In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input valid...
CVE-2019-2193HIGH7.8In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device ...
CVE-2019-2192HIGH7.8In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead ...
CVE-2019-2036CRITICAL9.8In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could...
CVE-2019-18279HIGH8.8In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application...
CVE-2019-16949MEDIUM6.5An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their ch...
CVE-2019-5294HIGH7.5There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corru...
CVE-2019-5293MEDIUM6.5Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation priv...
CVE-2019-5289HIGH7.5Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insuffici...
CVE-2019-16948CRITICAL9.8An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at We...
CVE-2019-5292LOW3.3Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9....
CVE-2019-4159Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-18931HIGH8.8Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) co...
CVE-2019-18930HIGH8.8Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbi...
CVE-2019-18929HIGH8.8Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arb...
CVE-2019-15948HIGH8.8Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote atta...
CVE-2019-5288HIGH7.8P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due...
CVE-2019-5287HIGH7.8P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due...
CVE-2019-18839CRITICAL9FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attack...
CVE-2019-17524MEDIUM5.4An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via...
CVE-2019-17523MEDIUM5.4An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now