2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-4369Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-4269HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Admin Console could allow a remote attacker to obtain sensitive ...
CVE-2019-9846RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreesto...
CVE-2019-13012The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_w...
CVE-2019-12997In Loopchain through 2.2.1.3, an attacker can escalate privileges from a low-privilege shell by changing the environment...
CVE-2019-12995Istio before 1.2.2 mishandles certain access tokens, leading to "Epoch 0 terminated with an error" in Envoy. This is rel...
CVE-2019-3632HIGH8.8Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows...
CVE-2019-3631HIGH7.2Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows a...
CVE-2019-3630HIGH7.2Command Injection vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows a...
CVE-2019-3629MEDIUM6.5Application protection bypass vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10....
CVE-2019-10177MEDIUM6.5A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and ...
CVE-2019-7225HIGH8.8The ABB HMI components implement hidden administrative accounts that are used during the provisioning phase of the HMI i...
CVE-2019-5840MEDIUM4.3Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass...
CVE-2019-5839MEDIUM4.3Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a...
CVE-2019-5838MEDIUM4.3Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinc...
CVE-2019-5837MEDIUM6.5Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cros...
CVE-2019-5836HIGH8.8Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit he...
CVE-2019-5835MEDIUM6.5Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially pe...
CVE-2019-5834MEDIUM6.5Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain...
CVE-2019-5833MEDIUM4.3Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to d...
CVE-2019-5832MEDIUM6.5Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to le...
CVE-2019-5831HIGH8.8Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit hea...
CVE-2019-5830MEDIUM6.5Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-o...
CVE-2019-5829HIGH8.8Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially per...
CVE-2019-5828HIGH8.8Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now