2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-10843Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-11065MEDIUM5.9Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or Coff...
CVE-2019-1573LOW2.5GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticat...
CVE-2019-9696Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a ty...
CVE-2019-8456MEDIUM5.9Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the in...
CVE-2019-6140CRITICAL9.8A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnera...
CVE-2019-5585An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application'...
CVE-2019-3842HIGH7In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t...
CVE-2019-0879A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0877A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, ...
CVE-2019-0876MEDIUM5.5An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memo...
CVE-2019-0875An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissio...
CVE-2019-0874A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided inpu...
CVE-2019-0871A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa...
CVE-2019-0870A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa...
CVE-2019-0869A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azu...
CVE-2019-0868A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa...
CVE-2019-0867A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa...
CVE-2019-0866A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sa...
CVE-2019-0862A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet ...
CVE-2019-0861A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2019-0860A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi...
CVE-2019-0859HIGH7.8An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2019-0858MEDIUM6.1A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web ...
CVE-2019-0857A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now