2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20925HIGH7.5An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause...
CVE-2019-14587MEDIUM6.5Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2019-14586HIGH8Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, in...
CVE-2019-14575HIGH7.8Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation...
CVE-2019-14563HIGH7.8Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local acc...
CVE-2019-2393MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-2392MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-20924MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which t...
CVE-2019-20923MEDIUM6.5A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which ...
CVE-2019-14562MEDIUM5.5Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of...
CVE-2019-14559HIGH7.5Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service vi...
CVE-2019-14553MEDIUM4.9Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network a...
CVE-2019-20933CRITICAL9.8InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler....
CVE-2019-12412HIGH7.5A flaw in the libapreq2 v2.07 to v2.13 multipart parser can deference a null pointer leading to a process crash. A remot...
CVE-2019-19563LOW2.4A misconfiguration in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with direct physical access to ...
CVE-2019-19562MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 2.1 allows an attacker with physical access to d...
CVE-2019-19561LOW2.4A misconfiguration in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with direct physical access to ...
CVE-2019-19560MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 1.5 allows an attacker with physical access to d...
CVE-2019-19557LOW2.4A misconfiguration in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with direct physical access to de...
CVE-2019-19556MEDIUM4.6An authentication bypass in the debug interface in Mercedes-Benz HERMES 1 allows an attacker with physical access to dev...
CVE-2019-17566HIGH7.5Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attri...
CVE-2019-11121HIGH7.8Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an au...
CVE-2019-7357HIGH8.8Subrion CMS 4.2.1 has CSRF in panel/modules/plugins/. The attacker can remotely activate/deactivate the plugins.
CVE-2019-7356MEDIUM5.4Subrion CMS v4.2.1 allows XSS via the panel/phrases/ VALUE parameter.
CVE-2019-4349LOW3.5IBM Maximo Anywhere 7.6.2.0, 7.6.2.1, 7.6.3.0, and 7.6.3.1 applications can be installed on a deprecated operating syste...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now