2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-7690In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from proce...
CVE-2019-4259MEDIUM5.5A security vulnerability has been identified in IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.2, 4.2.3, and 5.0.0 with CES...
CVE-2019-3684MEDIUM5.9SUSE Manager until version 4.0.7 and Uyuni until commit 1b426ad5ed0a7191a6fb46bb83e98ae4b99a5ade created world-readable ...
CVE-2019-12047Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution...
CVE-2019-11429CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)...
CVE-2019-8350MEDIUM6.6The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an informati...
CVE-2019-7411Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authentic...
CVE-2019-7409Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbi...
CVE-2019-7404An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file v...
CVE-2019-12043In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintabl...
CVE-2019-12041HIGH7.5lib/common/html_re.js in remarkable 1.7.1 allows Regular Expression Denial of Service (ReDoS) via a CDATA section.
CVE-2019-11888Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi...
CVE-2019-11886The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all...
CVE-2019-11885eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr...
CVE-2019-5438MEDIUM5.3Path traversal using symlink in npm harp module versions <= 0.29.0.
CVE-2019-5437Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i...
CVE-2019-11884LOW3.3The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to ob...
CVE-2019-5677NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-5676MEDIUM6.7NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly l...
CVE-2019-5675NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-3566MEDIUM5.9A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a...
CVE-2019-5496Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an ...
CVE-2019-5495OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security heade...
CVE-2019-11066openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method...
CVE-2019-11059Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now