2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0736CRITICAL9.8A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP respon...
CVE-2019-0723MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-0720HIGH8A remote code execution vulnerability exists when Windows Hyper-V Network Switch on a host server fails to properly vali...
CVE-2019-0718MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-0717MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-0716MEDIUM5.8A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully...
CVE-2019-0715MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-0714MEDIUM5.8A denial of service vulnerability exists when Microsoft Hyper-V Network Switch on a host server fails to properly valida...
CVE-2019-9583HIGH8.2eQ-3 Homematic CCU2 and CCU3 obtain session IDs without login. This allows a Denial of Service and is a starting point f...
CVE-2019-9582eQ-3 Homematic CCU2 outdated base software packages allows Denial of Service. CCU2 affected versions: 2.35.16, 2.41.5, 2...
CVE-2019-15052CRITICAL9.8The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If th...
CVE-2019-12262CRITICAL9.8Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vu...
CVE-2019-9506HIGH8.1The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and do...
CVE-2019-3639HIGH7.1Clickjack vulnerability in Adminstrator web console in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows remote ...
CVE-2019-3637MEDIUM6.7Privilege Escalation vulnerability in McAfee FRP 5.x prior to 5.1.0.209 allows local users to gain elevated privileges v...
CVE-2019-3635MEDIUM6.5Exfiltration of Data in McAfee Web Gateway (MWG) 7.8.2.x prior to 7.8.2.12 allows attackers to obtain sensitive data via...
CVE-2019-15053The "HTML Include and replace macro" plugin before 1.5.0 for Confluence Server allows a bypass of the includeScripts=fal...
CVE-2019-10201HIGH8.1It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacke...
CVE-2019-10199HIGH8.8It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An a...
CVE-2019-15050An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4A...
CVE-2019-15049An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4D...
CVE-2019-15048An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer overflow in the AP4_RtpAtom class at Core/Ap4Rtp...
CVE-2019-15047An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the function AP4_BitReader::SkipBit...
CVE-2019-14974SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
CVE-2019-11652A potential authorization bypass issue was found in Micro Focus Self Service Password Reset (SSPR) versions prior to: 4....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now