2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15212MEDIUM4.6An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the...
CVE-2019-15211MEDIUM4.6An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in ...
CVE-2019-11163Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows b...
CVE-2019-11162Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before ver...
CVE-2019-11148Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticate...
CVE-2019-11146Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote...
CVE-2019-11145HIGH7.8Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote...
CVE-2019-11143Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to p...
CVE-2019-11140Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es...
CVE-2019-0173Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attac...
CVE-2019-6178MEDIUM5.3An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details ...
CVE-2019-6171MEDIUM6.8A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrat...
CVE-2019-6165HIGH7.8A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege e...
CVE-2019-6159MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IM...
CVE-2019-5631HIGH7.8The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product...
CVE-2019-11276MEDIUM5.4Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5...
CVE-2019-15160The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (...
CVE-2019-15150HIGH8.8In the OAuth2 Client extension before 0.4 for MediaWiki, a CSRF vulnerability exists due to the OAuth2 state parameter n...
CVE-2019-15151CRITICAL9.8AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
CVE-2019-15149core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a c...
CVE-2019-15148GoPro GPMF-parser 1.2.2 has an out-of-bounds write in OpenMP4Source in demo/GPMF_mp4reader.c.
CVE-2019-15147GoPro GPMF-parser 1.2.2 has an out-of-bounds read and SEGV in GPMF_Next in GPMF_parser.c.
CVE-2019-15146GoPro GPMF-parser 1.2.2 has a heap-based buffer over-read (4 bytes) in GPMF_Next in GPMF_parser.c.
CVE-2019-15145MEDIUM5.5DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by c...
CVE-2019-15144MEDIUM5.5In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to cause a denial-of-se...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now