2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-0739A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft...
CVE-2019-0735An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper...
CVE-2019-0732A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind...
CVE-2019-0731An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak...
CVE-2019-0730An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak...
CVE-2019-0688An information disclosure vulnerability exists when the Windows TCP/IP stack improperly handles fragmented IP packets, a...
CVE-2019-0685An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ...
CVE-2019-7361An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trig...
CVE-2019-7360An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Au...
CVE-2019-7359An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk Au...
CVE-2019-7358An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk Aut...
CVE-2019-5513VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosu...
CVE-2019-5512VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately...
CVE-2019-5511VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle paths appropriately. Succ...
CVE-2019-1567The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML ...
CVE-2019-9134CRITICAL9.8Architectural Information System 1.0 and earlier versions have a Stack-based buffer overflow, allows remote attackers to...
CVE-2019-9133MEDIUM5.5When processing subtitles format media file, KMPlayer version 2018.12.24.14 or lower doesn't check object size correctly...
CVE-2019-8990HIGH8.1The HTTP Connector component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks contains a vulnerability that the...
CVE-2019-7174Roxy Fileman 1.4.5 allows attackers to execute renamefile.php (aka Rename File), createdir.php (aka Create Directory), f...
CVE-2019-6117The wpape APE GALLERY plugin 1.6.14 for WordPress has stored XSS via the classGallery.php getCategories function.
CVE-2019-5615MEDIUM6.5Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Globa...
CVE-2019-3941Advantech WebAccess 8.3.4 allows unauthenticated, remote attackers to delete arbitrary files via IOCTL 10005 RPC.
CVE-2019-3940Advantech WebAccess 8.3.4 is vulnerable to file upload attacks via unauthenticated RPC call. An unauthenticated, remote ...
CVE-2019-3893MEDIUM4.9In Foreman it was discovered that the delete compute resource operation, when executed from the Foreman API, leads to th...
CVE-2019-3887MEDIUM5.6A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtua...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now