2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-5305The image processing module of some Huawei Mate 10 smartphones versions before ALP-L29 9.0.0.159(C185) has a memory doub...
CVE-2019-5295Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.125(C00E125R2P14T8) have an authorization bypass ...
CVE-2019-5242There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can t...
CVE-2019-5241There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker...
CVE-2019-5219There is a double free vulnerability on certain drivers of Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0...
CVE-2019-5216There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C0...
CVE-2019-5214There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than A...
CVE-2019-12732The Chartkick gem through 3.1.0 for Ruby allows XSS.
CVE-2019-12134CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in Workday through 32 via a ...
CVE-2019-11080Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2...
CVE-2019-4220MEDIUM5.5IBM InfoSphere Information Server 11.7.1.0 stores a common hard coded encryption key that could be used to decrypt sensi...
CVE-2019-4201MEDIUM6.1IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow a remote attacker to conduct phishing attacks, u...
CVE-2019-4185HIGH8.3IBM InfoSphere Information Server 11.7.1 containers are vulnerable to privilege escalation due to an insecurely configur...
CVE-2019-4056MEDIUM4.3IBM Maximo Asset Management 7.6 Work Centers' application does not validate file type upon upload, allowing attackers to...
CVE-2019-4048LOW2.1IBM Maximo Asset Management 7.6 could allow a physical user of the system to obtain sensitive information from a previou...
CVE-2019-9158Gemalto DS3 Authentication Server 2.6.1-SP01 has Broken Access Control.
CVE-2019-9157Gemalto DS3 Authentication Server 2.6.1-SP01 allows Local File Disclosure.
CVE-2019-9156Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
CVE-2019-8385An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and loca...
CVE-2019-7672HIGH8.8Prima Systems FlexAir, Versions 2.3.38 and prior. The flash version of the web interface contains a hard-coded username ...
CVE-2019-7671CRITICAL9Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret...
CVE-2019-6800In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over ...
CVE-2019-12494HIGH8.5In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET r...
CVE-2019-9189Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when ...
CVE-2019-9187ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now