2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8076HIGH7.8Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Success...
CVE-2019-8070CRITICAL9.8Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability....
CVE-2019-8069CRITICAL9.8Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution ...
CVE-2019-11899HIGH7.5An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a cl...
CVE-2019-11898CRITICAL9.9Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The serv...
CVE-2019-14237CRITICAL9.8On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method...
CVE-2019-14236CRITICAL9.8On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protec...
CVE-2019-11774HIGH7.4Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pul...
CVE-2019-11773HIGH7.8Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevatio...
CVE-2019-6009MEDIUM6.1Open redirect vulnerability in SHIRASAGI v1.7.0 and earlier allows remote attackers to redirect users to arbitrary web s...
CVE-2019-6007HIGH8.8Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) con...
CVE-2019-6005CRITICAL9.8Smart TV Box firmware version prior to 1300 allows remote attackers to bypass access restriction to conduct arbitrary op...
CVE-2019-6004MEDIUM6.1Open redirect vulnerability in ApeosWare Management Suite Ver.1.4.0.18 and earlier, and ApeosWare Management Suite 2 Ver...
CVE-2019-6003MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remo...
CVE-2019-5996HIGH8.8SQL injection vulnerability in the Video Insight VMS 7.3.2.5 and earlier allows remote authenticated attackers to execut...
CVE-2019-5993HIGH8.8Cross-site request forgery (CSRF) vulnerability in Category Specific RSS feed Subscription version v2.0 and earlier allo...
CVE-2019-5992HIGH8.8Cross-site request forgery (CSRF) vulnerability in WordPress Ultra Simple Paypal Shopping Cart v4.4 and earlier allows r...
CVE-2019-5991HIGH7.6SQL injection vulnerability in the Cybozu Garoon 4.0.0 to 4.10.3 allows remote authenticated attackers to execute arbitr...
CVE-2019-5986HIGH8.8Cross-site request forgery (CSRF) vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay pr...
CVE-2019-5985MEDIUM6.1Cross-site scripting vulnerability in Hikari Denwa router/Home GateWay (Hikari Denwa router/Home GateWay provided by NIP...
CVE-2019-5978MEDIUM6.1Open redirect vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 allows remote attackers to redirect users to arbitrary web ...
CVE-2019-5977MEDIUM4.3Mail header injection vulnerability in Cybozu Garoon 4.0.0 to 4.10.2 may allow a remote authenticated attackers to alter...
CVE-2019-5976MEDIUM4.9Cybozu Garoon 4.0.0 to 4.10.2 allows an attacker with administrative rights to cause a denial of service condition via u...
CVE-2019-5975MEDIUM5.4DOM-based cross-site scripting vulnerability in Cybozu Garoon 4.6.0 to 4.10.2 allows remote authenticated attackers to i...
CVE-2019-5956MEDIUM6.5Directory traversal vulnerability in WonderCMS 2.6.0 and earlier allows remote attackers to delete arbitrary files via u...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now