2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5305 | — | — | 0.6% | Jun 6, 2019 | The image processing module of some Huawei Mate 10 smartphones versions before ALP-L29 9.0.0.159(C185) has a memory doub... |
| CVE-2019-5295 | — | — | 0.2% | Jun 6, 2019 | Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass ... |
| CVE-2019-5242 | — | — | 1.0% | Jun 6, 2019 | There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can t... |
| CVE-2019-5241 | — | — | 0.8% | Jun 6, 2019 | There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker... |
| CVE-2019-5219 | — | — | 0.5% | Jun 6, 2019 | There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0... |
| CVE-2019-5216 | — | — | 0.7% | Jun 6, 2019 | There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0... |
| CVE-2019-5214 | — | — | 0.6% | Jun 6, 2019 | There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than A... |
| CVE-2019-12732 | — | — | 0.8% | Jun 6, 2019 | The Chartkick gem through 3.1.0 for Ruby allows XSS. |
| CVE-2019-12134 | — | — | 1.4% | Jun 6, 2019 | CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a ... |
| CVE-2019-11080 | — | — | 14.2% | Jun 6, 2019 | Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2... |
| CVE-2019-4220 | MEDIUM | 5.5 | 0.2% | Jun 6, 2019 | IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensi... |
| CVE-2019-4201 | MEDIUM | 6.1 | 1.0% | Jun 6, 2019 | IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, u... |
| CVE-2019-4185 | HIGH | 8.3 | 0.6% | Jun 6, 2019 | IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configur... |
| CVE-2019-4056 | MEDIUM | 4.3 | 0.9% | Jun 6, 2019 | IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to... |
| CVE-2019-4048 | LOW | 2.1 | 0.3% | Jun 6, 2019 | IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previou... |
| CVE-2019-9158 | — | — | 1.0% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control. |
| CVE-2019-9157 | — | — | 0.7% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure. |
| CVE-2019-9156 | — | — | 3.2% | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection. |
| CVE-2019-8385 | — | — | 19.6% | Jun 5, 2019 | An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca... |
| CVE-2019-7672 | HIGH | 8.8 | 2.4% | Jun 5, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username ... |
| CVE-2019-7671 | CRITICAL | 9 | 8.3% | Jun 5, 2019 | Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret... |
| CVE-2019-6800 | — | — | 1.3% | Jun 5, 2019 | In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over ... |
| CVE-2019-12494 | HIGH | 8.5 | 1.9% | Jun 5, 2019 | In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET r... |
| CVE-2019-9189 | — | — | 11.6% | Jun 5, 2019 | Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when ... |
| CVE-2019-9187 | — | — | 1.7% | Jun 5, 2019 | ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact a... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now