2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15212 | MEDIUM | 4.6 | 0.8% | Aug 19, 2019 | An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the... |
| CVE-2019-15211 | MEDIUM | 4.6 | 0.8% | Aug 19, 2019 | An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in ... |
| CVE-2019-11163 | — | — | 0.4% | Aug 19, 2019 | Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows b... |
| CVE-2019-11162 | — | — | 0.4% | Aug 19, 2019 | Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before ver... |
| CVE-2019-11148 | — | — | 0.3% | Aug 19, 2019 | Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticate... |
| CVE-2019-11146 | — | — | 0.3% | Aug 19, 2019 | Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote... |
| CVE-2019-11145 | HIGH | 7.8 | 0.3% | Aug 19, 2019 | Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote... |
| CVE-2019-11143 | — | — | 0.4% | Aug 19, 2019 | Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to p... |
| CVE-2019-11140 | — | — | 0.4% | Aug 19, 2019 | Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es... |
| CVE-2019-0173 | — | — | 0.8% | Aug 19, 2019 | Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attac... |
| CVE-2019-6178 | MEDIUM | 5.3 | 1.1% | Aug 19, 2019 | An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details ... |
| CVE-2019-6171 | MEDIUM | 6.8 | 0.3% | Aug 19, 2019 | A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrat... |
| CVE-2019-6165 | HIGH | 7.8 | 0.4% | Aug 19, 2019 | A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege e... |
| CVE-2019-6159 | MEDIUM | 6.1 | 1.1% | Aug 19, 2019 | A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IM... |
| CVE-2019-5631 | HIGH | 7.8 | 1.1% | Aug 19, 2019 | The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product... |
| CVE-2019-11276 | MEDIUM | 5.4 | 0.3% | Aug 19, 2019 | Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5... |
| CVE-2019-15160 | — | — | 1.7% | Aug 19, 2019 | The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (... |
| CVE-2019-15150 | HIGH | 8.8 | 1.2% | Aug 19, 2019 | In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n... |
| CVE-2019-15151 | CRITICAL | 9.8 | 2.1% | Aug 18, 2019 | AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h. |
| CVE-2019-15149 | — | — | 1.6% | Aug 18, 2019 | core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a c... |
| CVE-2019-15148 | — | — | 1.1% | Aug 18, 2019 | GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c. |
| CVE-2019-15147 | — | — | 1.1% | Aug 18, 2019 | GoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c. |
| CVE-2019-15146 | — | — | 1.1% | Aug 18, 2019 | GoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c. |
| CVE-2019-15145 | MEDIUM | 5.5 | 1.6% | Aug 18, 2019 | DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by c... |
| CVE-2019-15144 | MEDIUM | 5.5 | 1.8% | Aug 18, 2019 | In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-se... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now