2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-15010HIGH8.8Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0...
CVE-2019-18271HIGH8.8OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request f...
CVE-2019-9510HIGH7.8A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne...
CVE-2019-16469HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. ...
CVE-2019-16468HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Succe...
CVE-2019-18412HIGH7.5JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2019-16784HIGH7.8In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic...
CVE-2019-13537HIGH7.5The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffe...
CVE-2019-19548HIGH7.8Norton Power Eraser, prior to 5.3.0.67, may be susceptible to a privilege escalation vulnerability, which is a type of i...
CVE-2019-10995HIGH8.8ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during t...
CVE-2019-12399HIGH7.5When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more ...
CVE-2019-19680HIGH8.8A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P...
CVE-2019-19728HIGH7.5SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
CVE-2019-20209HIGH7.5The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure ...
CVE-2019-18894HIGH7.8In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast...
CVE-2019-19475HIGH8.8An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-i...
CVE-2019-13767HIGH8.8Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the ...
CVE-2019-18194HIGH7.8TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio...
CVE-2019-14306HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).
CVE-2019-14304HIGH8.8Ricoh SP C250DN 1.06 devices allow CSRF.
CVE-2019-14301HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
CVE-2019-19820HIGH7.8An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an ...
CVE-2019-4508HIGH7.8IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local a...
CVE-2019-20373HIGH7.8LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the ...
CVE-2019-20184HIGH7.8KeePass 2.4.1 allows CSV injection in the title field of a CSV export.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now