2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11896HIGH7.1A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Ho...
CVE-2019-11895MEDIUM5.3A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (S...
CVE-2019-11894MEDIUM5.7A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC...
CVE-2019-6322HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS...
CVE-2019-6321HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS...
CVE-2019-11893HIGH8A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home...
CVE-2019-11892HIGH8A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (S...
CVE-2019-11891HIGH8A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Con...
CVE-2019-6958CRITICAL9.1A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI...
CVE-2019-6957CRITICAL9.8A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DI...
CVE-2019-12452types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable...
CVE-2019-12347In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description fiel...
CVE-2019-11872HIGH8.8The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it allows for injecting ma...
CVE-2019-7129Adobe Experience Manager Forms versions 6.2, 6.3 and 6.4 have a stored cross-site scripting vulnerability. Successful ex...
CVE-2019-9866An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.7.7 and 11.8.x before 11.8.3. It allow...
CVE-2019-9865When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer ove...
CVE-2019-9858HIGH8.8Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulner...
CVE-2019-9732An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11...
CVE-2019-9485An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo...
CVE-2019-9221An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x befo...
CVE-2019-12450CRITICAL9.8file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while ...
CVE-2019-12449MEDIUM5.7An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and grou...
CVE-2019-12448An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c has race conditions because the a...
CVE-2019-12447HIGH7.3An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because...
CVE-2019-12165CRITICAL9.8MiCollab 7.3 PR2 (7.3.0.204) and earlier, 7.2 (7.2.2.13) and earlier, and 7.1 (7.1.0.57) and earlier and MiCollab AWV 6....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now