2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10495HIGH7.3Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdrago...
CVE-2019-10491HIGH7.8ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Comput...
CVE-2019-10488HIGH7.5Null pointer dereference can occur while parsing invalid chunks while playing the nonstandard clip in Snapdragon Auto, S...
CVE-2019-18800HIGH8.8Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account...
CVE-2019-18799MEDIUM6.5LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp.
CVE-2019-18798MEDIUM6.5LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp.
CVE-2019-18797MEDIUM6.5LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp.
CVE-2019-13081MEDIUM5.4Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /comm...
CVE-2019-13080MEDIUM5.4Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) ...
CVE-2019-13079HIGH8.8Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ...
CVE-2019-13078HIGH8.8Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ...
CVE-2019-13077MEDIUM6.1Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SA...
CVE-2019-13076HIGH8.8Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ...
CVE-2019-12918CRITICAL9.8Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file ...
CVE-2019-12917MEDIUM6.1A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the user...
CVE-2019-14847MEDIUM4.9A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP se...
CVE-2019-14833MEDIUM5.4A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the wa...
CVE-2019-10218MEDIUM6.5A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious serv...
CVE-2019-18786MEDIUM5.5In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/plat...
CVE-2019-18784CRITICAL9.8SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection.
CVE-2019-18674MEDIUM5.3An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a pa...
CVE-2019-18650HIGH8.8An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability.
CVE-2019-8158CRITICAL9.8An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A...
CVE-2019-8157MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2...
CVE-2019-8156HIGH7.2A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now