2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-15028In Joomla! before 3.9.11, inadequate checks in com_contact could allow mail submission in disabled forms.
CVE-2019-9518HIGH7.5Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The a...
CVE-2019-9517HIGH7.5Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of s...
CVE-2019-9516MEDIUM6.5Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker se...
CVE-2019-9515HIGH7.5Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker...
CVE-2019-9514HIGH7.5Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker op...
CVE-2019-9513HIGH7.5Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker c...
CVE-2019-9512HIGH7.5Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker send...
CVE-2019-9511HIGH7.5Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potential...
CVE-2019-5299Huawei mobile phones Hima-AL00Bhave with Versions earlier than HMA-AL00C00B175 have a signature verification bypass vuln...
CVE-2019-5280The SIP TLS module of Huawei CloudLink Phone 7900 with V600R019C10 has a TLS certificate verification vulnerability. Due...
CVE-2019-5223PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not pe...
CVE-2019-14809net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization by...
CVE-2019-12479An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in t...
CVE-2019-11207HIGH8.8The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Ma...
CVE-2019-14986eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn before 2.3.0 installed allow administrative operations by unauthenticat...
CVE-2019-14985eQ-3 Homematic CCU2 and CCU3 with the CUxD AddOn installed allow Remote Code Execution by unauthenticated attackers with...
CVE-2019-14984eQ-3 Homematic CCU2 and CCU3 with the XML-API through 1.2.0 AddOn installed allow Remote Code Execution by unauthenticat...
CVE-2019-12808HIGH7.8ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure per...
CVE-2019-12807HIGH7.8Alzip 10.83 and earlier version contains a stack-based buffer overflow vulnerability, caused by improper bounds checking...
CVE-2019-12806HIGH8.8UniSign 2.0.4.0 and earlier version contains a stack-based buffer overflow vulnerability which can overwrite the stack w...
CVE-2019-13416MEDIUM6.5Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are alwa...
CVE-2019-13415MEDIUM6.5Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users can gain...
CVE-2019-10943HIGH7.5A vulnerability has been identified in SIMATIC Drive Controller family (All versions), SIMATIC ET 200SP Open Controller ...
CVE-2019-10942HIGH8.6A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5),...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now