2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1924HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2019-1918HIGH7.4A vulnerability in the implementation of Intermediate System–to–Intermediate System (IS–IS) routing pr...
CVE-2019-14763MEDIUM5.5In the Linux kernel before 4.16.4, a double-locking error in drivers/usb/dwc3/gadget.c may potentially cause a deadlock ...
CVE-2019-1925HIGH7.8Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Micros...
CVE-2019-1910HIGH7.4A vulnerability in the implementation of the Intermediate System–to–Intermediate System (IS–IS) routin...
CVE-2019-1895CRITICAL9.8A vulnerability in the Virtual Network Computing (VNC) console implementation of Cisco Enterprise NFV Infrastructure Sof...
CVE-2019-14474eQ-3 Homematic CCU3 3.47.15 and prior has Improper Input Validation in function 'Call()' of ReGa core logic process, res...
CVE-2019-5476CRITICAL9.8An SQL Injection in the Nextcloud Lookup-Server < v0.3.0 (running on https://lookup.nextcloud.com) caused unauthenticate...
CVE-2019-14750MEDIUM6.1An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It w...
CVE-2019-14749HIGH8.8An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. CSV (aka Formula) injection exists in the ex...
CVE-2019-14748MEDIUM5.4An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl...
CVE-2019-14537YOURLS through 1.7.3 is affected by a type juggling vulnerability in the api component that can result in login bypass.
CVE-2019-11653Remote Access Control Bypass in Micro Focus Content Manager. versions 9.1, 9.2, 9.3. The vulnerability could be exploite...
CVE-2019-10099HIGH7.5Prior to Spark 2.3.3, in certain situations Spark would write user data to local disk unencrypted, even if spark.io.encr...
CVE-2019-14747DWSurvey through 2019-07-22 has stored XSS via the design/my-survey-design!copySurvey.action surveyName parameter.
CVE-2019-14746A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parame...
CVE-2019-14745HIGH7.8In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a craft...
CVE-2019-14744HIGH7.8In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with min...
CVE-2019-14743In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" ...
CVE-2019-14432Incorrect authentication of application WebSocket connections in Loom Desktop for Mac up to 0.16.0 allows remote code ex...
CVE-2019-10389MEDIUM4.3A missing permission check in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier allows attackers to...
CVE-2019-10388MEDIUM4.3A cross-site request forgery vulnerability in Jenkins Relution Enterprise Appstore Publisher Plugin 1.24 and earlier all...
CVE-2019-10387MEDIUM6.5A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnecti...
CVE-2019-10386HIGH8.8A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescripto...
CVE-2019-10385MEDIUM6.5Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master whe...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now