2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-12315Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "...
CVE-2019-12195TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking ...
CVE-2019-12155interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
CVE-2019-12150Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extens...
CVE-2019-11876In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by ...
CVE-2019-11875In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exp...
CVE-2019-12314Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as ...
CVE-2019-12313XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
CVE-2019-12312In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer de...
CVE-2019-5804MEDIUM5.5Incorrect command line processing in Chrome in Google Chrome prior to 73.0.3683.75 allowed a local attacker to perform d...
CVE-2019-5803MEDIUM6.5Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 73.0.3683.75 allowed a remote attac...
CVE-2019-5802MEDIUM6.5Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to...
CVE-2019-5801MEDIUM6.5Incorrect eliding of URLs in Omnibox in Google Chrome on iOS prior to 73.0.3683.75 allowed a remote attacker to perform ...
CVE-2019-5800MEDIUM6.5Insufficient policy enforcement in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to bypass cont...
CVE-2019-5799MEDIUM6.5Incorrect inheritance of a new document's policy in Content Security Policy in Google Chrome prior to 73.0.3683.75 allow...
CVE-2019-5798MEDIUM6.5Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an o...
CVE-2019-5796HIGH7.5Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo...
CVE-2019-5795HIGH8.8Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out o...
CVE-2019-5794MEDIUM6.5Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker ...
CVE-2019-5793MEDIUM6.5Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initia...
CVE-2019-5792HIGH8.8Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out o...
CVE-2019-5791HIGH8.8Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of b...
CVE-2019-5790HIGH8.8An integer overflow leading to an incorrect capacity of a buffer in JavaScript in Google Chrome prior to 73.0.3683.75 al...
CVE-2019-5789HIGH8.8An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed ...
CVE-2019-5788HIGH8.8An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now