2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13743 | MEDIUM | 6.5 | 1.3% | Dec 10, 2019 | Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to ... |
| CVE-2019-13742 | MEDIUM | 6.5 | 1.3% | Dec 10, 2019 | Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the co... |
| CVE-2019-13740 | MEDIUM | 6.5 | 0.8% | Dec 10, 2019 | Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoo... |
| CVE-2019-13739 | MEDIUM | 6.5 | 1.3% | Dec 10, 2019 | Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform d... |
| CVE-2019-13738 | MEDIUM | 6.5 | 1.3% | Dec 10, 2019 | Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass... |
| CVE-2019-13737 | MEDIUM | 6.5 | 1.4% | Dec 10, 2019 | Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obta... |
| CVE-2019-13672 | MEDIUM | 6.5 | 0.6% | Dec 10, 2019 | Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof t... |
| CVE-2019-19703 | MEDIUM | 6.1 | 0.6% | Dec 10, 2019 | In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location. |
| CVE-2019-6192 | MEDIUM | 4.4 | 1.7% | Dec 10, 2019 | A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a ... |
| CVE-2019-4663 | MEDIUM | 5.4 | 0.7% | Dec 10, 2019 | IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2019-4095 | MEDIUM | 4.3 | 0.4% | Dec 10, 2019 | IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ... |
| CVE-2019-19251 | MEDIUM | 5.3 | 0.7% | Dec 10, 2019 | The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without ... |
| CVE-2019-19698 | MEDIUM | 6.5 | 1.2% | Dec 10, 2019 | marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c. |
| CVE-2019-4611 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2019-4428 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerab... |
| CVE-2019-18380 | MEDIUM | 6.5 | 0.6% | Dec 9, 2019 | Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue... |
| CVE-2019-19682 | MEDIUM | 4.8 | 0.6% | Dec 9, 2019 | nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Control... |
| CVE-2019-19679 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condi... |
| CVE-2019-19678 | MEDIUM | 5.4 | 0.6% | Dec 9, 2019 | In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic f... |
| CVE-2019-19645 | MEDIUM | 5.5 | 0.6% | Dec 9, 2019 | alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential vi... |
| CVE-2019-16772 | MEDIUM | 6.1 | 0.6% | Dec 7, 2019 | The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly m... |
| CVE-2019-9464 | MEDIUM | 5.5 | 0.4% | Dec 6, 2019 | In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is ... |
| CVE-2019-2231 | MEDIUM | 4.4 | 0.1% | Dec 6, 2019 | In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead ... |
| CVE-2019-2229 | MEDIUM | 5.5 | 0.1% | Dec 6, 2019 | In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. Thi... |
| CVE-2019-2228 | MEDIUM | 5.5 | 0.2% | Dec 6, 2019 | In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now