2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2199 | MEDIUM | 6.7 | 0.2% | Nov 13, 2019 | In createSessionInternal of PackageInstallerService.java, there is a possible permissions bypass. This could lead to loc... |
| CVE-2019-2198 | MEDIUM | 5.5 | 0.4% | Nov 13, 2019 | In Download Provider, there is a possible SQL injection vulnerability. This could lead to local information disclosure w... |
| CVE-2019-2197 | MEDIUM | 5.5 | 0.2% | Nov 13, 2019 | In processPhonebookAccess of CachedBluetoothDevice.java, there is a possible permission bypass due to an insecure defaul... |
| CVE-2019-2196 | MEDIUM | 5.5 | 0.4% | Nov 13, 2019 | In Download Provider, there is possible SQL injection. This could lead to local information disclosure with no additiona... |
| CVE-2019-2195 | HIGH | 7.8 | 0.2% | Nov 13, 2019 | In tokenize of sqlite3_android.cpp, there is a possible attacker controlled INSERT statement due to improper input valid... |
| CVE-2019-2193 | HIGH | 7.8 | 0.2% | Nov 13, 2019 | In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device ... |
| CVE-2019-2192 | HIGH | 7.8 | 0.2% | Nov 13, 2019 | In call of SliceProvider.java, there is a possible permissions bypass due to improper input validation. This could lead ... |
| CVE-2019-2036 | CRITICAL | 9.8 | 2.0% | Nov 13, 2019 | In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could... |
| CVE-2019-18279 | HIGH | 8.8 | 1.3% | Nov 13, 2019 | In Phoenix SCT WinFlash 1.1.12.0 through 1.5.74.0, the included drivers could be used by a malicious Windows application... |
| CVE-2019-16949 | MEDIUM | 6.5 | 0.8% | Nov 13, 2019 | An issue was discovered in Enghouse Web Chat 6.1.300.31 and 6.2.284.34. A user is allowed to send an archive of their ch... |
| CVE-2019-5294 | HIGH | 7.5 | 0.9% | Nov 13, 2019 | There is an out of bound read vulnerability in some Huawei products. A remote, unauthenticated attacker may send a corru... |
| CVE-2019-5293 | MEDIUM | 6.5 | 0.8% | Nov 13, 2019 | Some Huawei products have a memory leak vulnerability when handling some messages. A remote attacker with operation priv... |
| CVE-2019-5289 | HIGH | 7.5 | 0.7% | Nov 13, 2019 | Gauss100 OLTP database in ManageOne with versions of 6.5.0 have an out-of-bounds read vulnerability due to the insuffici... |
| CVE-2019-16948 | CRITICAL | 9.8 | 1.3% | Nov 13, 2019 | An SSRF issue was discovered in Enghouse Web Chat 6.1.300.31. In any POST request, one can replace the port number at We... |
| CVE-2019-5292 | LOW | 3.3 | 0.2% | Nov 13, 2019 | Honor 10 Lite, Honor 8A, Huawei Y6 mobile phones with the versions before 9.1.0.217(C00E215R3P1), the versions before 9.... |
| CVE-2019-4159 | — | — | — | Nov 13, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-18931 | HIGH | 8.8 | 2.2% | Nov 13, 2019 | Western Digital My Cloud EX2 Ultra firmware 2.31.195 allows a Buffer Overflow with Extended Instruction Pointer (EIP) co... |
| CVE-2019-18930 | HIGH | 8.8 | 3.2% | Nov 13, 2019 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest account) to remotely execute arbi... |
| CVE-2019-18929 | HIGH | 8.8 | 2.9% | Nov 13, 2019 | Western Digital My Cloud EX2 Ultra firmware 2.31.183 allows web users (including guest accounts) to remotely execute arb... |
| CVE-2019-15948 | HIGH | 8.8 | 2.5% | Nov 13, 2019 | Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote atta... |
| CVE-2019-5288 | HIGH | 7.8 | 0.9% | Nov 13, 2019 | P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due... |
| CVE-2019-5287 | HIGH | 7.8 | 0.9% | Nov 13, 2019 | P30 smart phones with versions earlier than ELLE-AL00B 9.1.0.193(C00E190R2P1) have an integer overflow vulnerability due... |
| CVE-2019-18839 | CRITICAL | 9 | 5.4% | Nov 13, 2019 | FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attack... |
| CVE-2019-17524 | MEDIUM | 5.4 | 0.8% | Nov 13, 2019 | An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via... |
| CVE-2019-17523 | MEDIUM | 5.4 | 0.6% | Nov 13, 2019 | An XSS vulnerability on Technicolor TC7300 STFA.51.20 devices allows remote attackers to inject arbitrary web script via... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now