2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6774HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.168...
CVE-2019-13320HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13319HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13318MEDIUM5.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9...
CVE-2019-13317HIGH7.8This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0....
CVE-2019-13316HIGH7.8This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0....
CVE-2019-13315HIGH7.8This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.2072...
CVE-2019-17178HIGH7.5HuffmanTree_makeFromFrequencies in lodepng.c in LodePNG through 2019-09-28, as used in WinPR in FreeRDP and other produc...
CVE-2019-17177HIGH7.5libfreerdp/codec/region.c in FreeRDP through 1.1.x and 2.x through 2.0.0-rc4 has memory leaks because a supplied realloc...
CVE-2019-17175HIGH7.5joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
CVE-2019-4564MEDIUM6.1IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2019-4514MEDIUM5.3IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0, and 3.0.1 discloses sensitive information to unauthorized users. The i...
CVE-2019-4227HIGH7.3IBM MQ 8.0.0.4 - 8.0.0.12, 9.0.0.0 - 9.0.0.6, 9.1.0.0 - 9.1.0.2, and 9.1.0 - 9.1.2 AMQP Listeners could allow an unautho...
CVE-2019-16891CRITICAL9.8Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.
CVE-2019-17133CRITICAL9.8In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE,...
CVE-2019-17132CRITICAL9.8vBulletin through 5.5.4 mishandles custom avatars.
CVE-2019-17131MEDIUM4.3vBulletin before 5.5.4 allows clickjacking.
CVE-2019-17130MEDIUM6.5vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.
CVE-2019-17121MEDIUM5.4REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
CVE-2019-17113CRITICAL9.8In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug....
CVE-2019-13332HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.6.0.251...
CVE-2019-13331HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13330HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13329HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5. User...
CVE-2019-13328HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now