2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2019-19012CRITICAL9.8An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bo...
CVE-2019-19010CRITICAL9.8Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivi...
CVE-2019-13582CRITICAL9.8An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa...
CVE-2019-13581CRITICAL9.8An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufa...
CVE-2019-14345CRITICAL9.8TemaTres 3.0 allows remote unprivileged users to create an administrator account
CVE-2019-18985CRITICAL9.8Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
CVE-2019-18981CRITICAL9.8Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notificatio...
CVE-2019-18928CRITICAL9.8Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpre...
CVE-2019-15803CRITICAL9.1An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Through an undocumented sequence of...
CVE-2019-15800CRITICAL9.8An issue was discovered on Zyxel GS1900 devices with firmware before 2.50(AAHH.0)C0. Due to lack of input validation in ...
CVE-2019-14678CRITICAL10SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multi...
CVE-2019-18939CRITICAL9.8eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the HM-Print AddOn through 1.2a installed allow Remote Code Execution ...
CVE-2019-18938CRITICAL9.8eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the E-Mail AddOn through 1.6.8.c installed allow Remote Code Execution...
CVE-2019-18937CRITICAL9.8eQ-3 Homematic CCU2 2.47.20 and CCU3 3.47.18 with the Script Parser AddOn through 1.8 installed allow Remote Code Execut...
CVE-2019-11171CRITICAL9.8Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially en...
CVE-2019-11168CRITICAL9.1Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user t...
CVE-2019-8248CRITICAL9.8Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2019-8247CRITICAL9.8Adobe Illustrator CC versions 23.1 and earlier have a memory corruption vulnerability. Successful exploitation could lea...
CVE-2019-8246CRITICAL9.8Adobe Media Encoder versions 13.1 and earlier have an out-of-bounds write vulnerability. Successful exploitation could l...
CVE-2019-5029CRITICAL9.8An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7...
CVE-2019-18952CRITICAL9.8SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951...
CVE-2019-18240CRITICAL9.8In Fuji Electric V-Server 4.0.6 and prior, several heap-based buffer overflows have been identified, which may allow an ...
CVE-2019-2205CRITICAL9.8In ProxyResolverV8::SetPacScript of proxy_resolver_v8.cc, there is a possible memory corruption due to a use after free....
CVE-2019-2204CRITICAL9.8In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This ...
CVE-2019-2036CRITICAL9.8In okToConnect of HidHostService.java, there is a possible permission bypass due to an incorrect state check. This could...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now