2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13633MEDIUM6.1Blinger.io v.1.0.2519 is vulnerable to Blind/Persistent XSS. An attacker can send arbitrary JavaScript code via a built-...
CVE-2019-12305MEDIUM6.5In EZCast Pro II, the administrator password md5 hash is provided upon a web request. This hash can be cracked to access...
CVE-2019-19885CRITICAL9.1In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge a...
CVE-2019-19513CRITICAL9.8The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability....
CVE-2019-18796MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinit...
CVE-2019-18795MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a c...
CVE-2019-18794MEDIUM6.5The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a craft...
CVE-2019-17640CRITICAL9.8In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.miles...
CVE-2019-12411Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-4552MEDIUM6.1IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attack...
CVE-2019-2194HIGH7.8In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casti...
CVE-2019-17444CRITICAL9.8Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to ...
CVE-2019-19115HIGH7.8An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 a...
CVE-2019-4545HIGH7.5IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attack...
CVE-2019-16160HIGH7.5An integer underflow in the SMB server of MikroTik RouterOS before 6.45.5 allows remote unauthenticated attackers to cra...
CVE-2019-4326HIGH7.5"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Stri...
CVE-2019-4325MEDIUM5.3"HCL AppScan Enterprise makes use of broken or risky cryptographic algorithm to store REST API user details."
CVE-2019-4725MEDIUM6.1IBM Security Access Manager Appliance 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2019-19200HIGH8.8REDDOXX MailDepot 2032 2.2.1242 allows authenticated users to access the mailboxes of other users.
CVE-2019-14558MEDIUM5.7Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(...
CVE-2019-14557HIGH8Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5...
CVE-2019-14556MEDIUM4.4Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor ...
CVE-2019-19199HIGH7.4REDDOXX MailDepot 2032 SP2 2.2.1242 has Insufficient Session Expiration because tokens are not invalidated upon a logout...
CVE-2019-19393MEDIUM6.1The Web application on Rittal CMC PU III 7030.000 V3.00 V3.11.00_2 to V3.15.70_4 devices fails to sanitize user input on...
CVE-2019-20903MEDIUM5.4The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitra...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now