2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-19854HIGH8.8An issue was discovered in Serpico (aka SimplE RePort wrIting and CollaboratiOn tool) 1.3.0. It does not use CSRF Tokens...
CVE-2019-20097HIGH8.8Bitbucket Server and Bitbucket Data Center versions starting from 1.0.0 before 5.16.11, from version 6.0.0 before 6.0.11...
CVE-2019-15012HIGH8.8Bitbucket Server and Bitbucket Data Center from version 4.13. before 5.16.11, from version 6.0.0 before 6.0.11, from ver...
CVE-2019-15010HIGH8.8Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0...
CVE-2019-18271HIGH8.8OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request f...
CVE-2019-9510HIGH7.8A vulnerability in Microsoft Windows 10 1803 and Windows Server 2019 and later systems can allow authenticated RDP-conne...
CVE-2019-16469HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. ...
CVE-2019-16468HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Succe...
CVE-2019-18412HIGH7.5JetBrains IDETalk plugin before version 193.4099.10 allows XXE
CVE-2019-16784HIGH7.8In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this partic...
CVE-2019-13537HIGH7.5The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffe...
CVE-2019-19548HIGH7.8Norton Power Eraser, prior to 5.3.0.67, may be susceptible to a privilege escalation vulnerability, which is a type of i...
CVE-2019-10995HIGH8.8ABB CP651 HMI products revision BSP UN30 v1.76 and prior implement hidden administrative accounts that are used during t...
CVE-2019-12399HIGH7.5When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more ...
CVE-2019-19680HIGH8.8A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P...
CVE-2019-19728HIGH7.5SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
CVE-2019-20209HIGH7.5The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure ...
CVE-2019-18894HIGH7.8In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast...
CVE-2019-19475HIGH8.8An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-i...
CVE-2019-13767HIGH8.8Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the ...
CVE-2019-18194HIGH7.8TotalAV 2020 4.14.31 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junctio...
CVE-2019-14306HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 2 of 2).
CVE-2019-14304HIGH8.8Ricoh SP C250DN 1.06 devices allow CSRF.
CVE-2019-14301HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
CVE-2019-19820HIGH7.8An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now