2019 CVE Vulnerabilities
17,621 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10495 | HIGH | 7.3 | 0.2% | Nov 6, 2019 | Arbitrary buffer write issue while processing sequence header during HEVC or AVC encoding. in Snapdragon Auto, Snapdrago... |
| CVE-2019-10491 | HIGH | 7.8 | 0.2% | Nov 6, 2019 | ADSP can be compromised since it`s a general-purpose CPU processing untrusted data in Snapdragon Auto, Snapdragon Comput... |
| CVE-2019-10488 | HIGH | 7.5 | 0.8% | Nov 6, 2019 | Null pointer dereference can occur while parsing invalid chunks while playing the nonstandard clip in Snapdragon Auto, S... |
| CVE-2019-18800 | HIGH | 8.8 | 1.4% | Nov 6, 2019 | Viber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account... |
| CVE-2019-18799 | MEDIUM | 6.5 | 1.3% | Nov 6, 2019 | LibSass before 3.6.3 allows a NULL pointer dereference in Sass::Parser::parseCompoundSelector in parser_selectors.cpp. |
| CVE-2019-18798 | MEDIUM | 6.5 | 1.1% | Nov 6, 2019 | LibSass before 3.6.3 allows a heap-based buffer over-read in Sass::weaveParents in ast_sel_weave.cpp. |
| CVE-2019-18797 | MEDIUM | 6.5 | 1.5% | Nov 6, 2019 | LibSass 3.6.1 has uncontrolled recursion in Sass::Eval::operator()(Sass::Binary_Expression*) in eval.cpp. |
| CVE-2019-13081 | MEDIUM | 5.4 | 0.8% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /comm... |
| CVE-2019-13080 | MEDIUM | 5.4 | 0.8% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) ... |
| CVE-2019-13079 | HIGH | 8.8 | 1.2% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ... |
| CVE-2019-13078 | HIGH | 8.8 | 1.2% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ... |
| CVE-2019-13077 | MEDIUM | 6.1 | 1.0% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SA... |
| CVE-2019-13076 | HIGH | 8.8 | 1.2% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has ... |
| CVE-2019-12918 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file ... |
| CVE-2019-12917 | MEDIUM | 6.1 | 1.0% | Nov 6, 2019 | A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the user... |
| CVE-2019-14847 | MEDIUM | 4.9 | 2.4% | Nov 6, 2019 | A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP se... |
| CVE-2019-14833 | MEDIUM | 5.4 | 2.1% | Nov 6, 2019 | A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the wa... |
| CVE-2019-10218 | MEDIUM | 6.5 | 3.5% | Nov 6, 2019 | A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious serv... |
| CVE-2019-18786 | MEDIUM | 5.5 | 0.3% | Nov 6, 2019 | In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized in rcar_drif_g_fmt_sdr_cap in drivers/media/plat... |
| CVE-2019-18784 | CRITICAL | 9.8 | 1.1% | Nov 6, 2019 | SuiteCRM 7.10.x versions prior to 7.10.21 and 7.11.x versions prior to 7.11.9 allow SQL Injection. |
| CVE-2019-18674 | MEDIUM | 5.3 | 1.1% | Nov 6, 2019 | An issue was discovered in Joomla! before 3.9.13. A missing access check in the phputf8 mapping files could lead to a pa... |
| CVE-2019-18650 | HIGH | 8.8 | 0.5% | Nov 6, 2019 | An issue was discovered in Joomla! before 3.9.13. A missing token check in com_template causes a CSRF vulnerability. |
| CVE-2019-8158 | CRITICAL | 9.8 | 1.3% | Nov 6, 2019 | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. A... |
| CVE-2019-8157 | MEDIUM | 5.4 | 0.6% | Nov 6, 2019 | A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2... |
| CVE-2019-8156 | HIGH | 7.2 | 1.7% | Nov 6, 2019 | A server-side request forgery (SSRF) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now