2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12280PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
CVE-2019-6329HIGH7.8HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d...
CVE-2019-6328HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of d...
CVE-2019-4382MEDIUM5.3IBM API Connect 5.0.0.0 through 5.0.8.6 could allow an unauthorized user to obtain sensitive information about the syste...
CVE-2019-4377MEDIUM4.3IBM Sterling B2B Integrator 6.0.0.0 and 6.0.0.1 reveals sensitive information from a stack trace that could be used in f...
CVE-2019-4158MEDIUM5.4IBM Security Access Manager 9.0.1 through 9.0.6 does not prove that a user's identity is correct which can lead to the e...
CVE-2019-4157MEDIUM6.1IBM Security Access Manager 9.0.1 through 9.0.6 is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2019-4156MEDIUM5.9IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2019-4153MEDIUM6.8IBM Security Access Manager 9.0.1 through 9.0.6 could allow a remote attacker to conduct phishing attacks, using an open...
CVE-2019-4152MEDIUM4.4IBM Security Access Manager 9.0.1 through 9.0.6 does not invalidate session tokens in a timely manner. The lack of prope...
CVE-2019-4151MEDIUM5.9IBM Security Access Manager 9.0.1 through 9.0.6 uses weaker than expected cryptographic algorithms that could allow an a...
CVE-2019-4150LOW3.7IBM Security Access Manager 9.0.1 through 9.0.6 does not validate, or incorrectly validates, a certificate which could a...
CVE-2019-4145HIGH7.1IBM Security Access Manager 9.0.1 through 9.0.6 could reveal highly sensitive in specialized conditions to a local user ...
CVE-2019-4135HIGH8.8IBM Security Access Manager 9.0.1 through 9.0.6 is affected by a security vulnerability that could allow authenticated u...
CVE-2019-12964LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject.
CVE-2019-12963LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action.
CVE-2019-12962MEDIUM6.1LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
CVE-2019-12961LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function.
CVE-2019-12960LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_d...
CVE-2019-12817HIGH7arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes...
CVE-2019-12949In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on...
CVE-2019-12958In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in FoFiType1C::convertToType0 in fofi/FoFiType1C.cc wh...
CVE-2019-12957HIGH7.8In Xpdf 4.01.01, a buffer over-read could be triggered in FoFiType1C::convertToType1 in fofi/FoFiType1C.cc when the inde...
CVE-2019-12951An issue was discovered in Mongoose before 6.15. The parse_mqtt() function in mg_mqtt.c has a critical heap-based buffer...
CVE-2019-10689VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) applicatio...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now