2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-9842madskristensen MiniBlog through 2018-05-18 allows remote attackers to execute arbitrary ASPX code via an IMG element wit...
CVE-2019-12828An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and orig...
CVE-2019-0316SAP NetWeaver Process Integration, versions: SAP_XIESR: 7.20, SAP_XITOOL: 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50, does not...
CVE-2019-0303SAP BusinessObjects Business Intelligence Platform (Administration Console), versions 4.2, 4.3, module BILogon/appServic...
CVE-2019-2259Resource allocation error while playing the video whose dimensions are more than supported dimension in Snapdragon Auto,...
CVE-2019-2257Wrong permissions in configuration file can lead to unauthorized permission in Snapdragon Auto, Snapdragon Connectivity,...
CVE-2019-2256An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr...
CVE-2019-2255An unprivileged user can craft a bitstream such that the payload encoded in the bitstream gains code execution in Snapdr...
CVE-2019-4403MEDIUM5.4IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript...
CVE-2019-4381MEDIUM5.5IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node...
CVE-2019-4239MEDIUM5.5IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which c...
CVE-2019-12822In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory asserti...
CVE-2019-11770HIGH8.1In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over ...
CVE-2019-11582An argument injection vulnerability in Atlassian Sourcetree for Windows's URI handlers, in all versions prior to 3.1.3, ...
CVE-2019-10159MEDIUM4.3cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorizati...
CVE-2019-10126CRITICAL9.8A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net...
CVE-2019-12819An issue was discovered in the Linux kernel before 5.0. The function __mdiobus_register() in drivers/net/phy/mdio_bus.c ...
CVE-2019-12818An issue was discovered in the Linux kernel before 4.20.15. The nfc_llcp_build_tlv function in net/nfc/llcp_commands.c m...
CVE-2019-12813An issue was discovered in Digital Persona U.are.U 4500 Fingerprint Reader v24. The key and salt used for obfuscating th...
CVE-2019-12802HIGH7.8In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remot...
CVE-2019-10962MEDIUM5.3BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on ...
CVE-2019-10959BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13,...
CVE-2019-12799HIGH8.8In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat...
CVE-2019-7321Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vuln...
CVE-2019-12798An issue was discovered in Artifex MuJS 1.0.5. regcompx in regexp.c does not restrict regular expression program size, l...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now