2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-13743MEDIUM6.5Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to ...
CVE-2019-13742MEDIUM6.5Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the co...
CVE-2019-13740MEDIUM6.5Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoo...
CVE-2019-13739MEDIUM6.5Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform d...
CVE-2019-13738MEDIUM6.5Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass...
CVE-2019-13737MEDIUM6.5Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obta...
CVE-2019-13672MEDIUM6.5Incorrect security UI in Omnibox in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially spoof t...
CVE-2019-19703MEDIUM6.1In Ktor through 1.2.6, the client resends data from the HTTP Authorization header to a redirect location.
CVE-2019-6192MEDIUM4.4A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a ...
CVE-2019-4663MEDIUM5.4IBM WebSphere Application Server - Liberty is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2019-4095MEDIUM4.3IBM Cloud Pak System 2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious ...
CVE-2019-19251MEDIUM5.3The Last.fm desktop app (Last.fm Scrobbler) through 2.1.39 on macOS makes HTTP requests that include an API key without ...
CVE-2019-19698MEDIUM6.5marc-q libwav through 2017-04-20 has a NULL pointer dereference in wav_content_read() at libwav.c.
CVE-2019-4611MEDIUM5.4IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2019-4428MEDIUM5.4IBM Watson Assistant for IBM Cloud Pak for Data 1.0.0 through 1.3.0 is vulnerable to cross-site scripting. This vulnerab...
CVE-2019-18380MEDIUM6.5Symantec Industrial Control System Protection (ICSP), versions 6.x.x, may be susceptible to an unauthorized access issue...
CVE-2019-19682MEDIUM4.8nopCommerce through 4.20 allows XSS in the SaveStoreMappings of the components \Presentation\Nop.Web\Areas\Admin\Control...
CVE-2019-19679MEDIUM5.4In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the Pre-Condi...
CVE-2019-19678MEDIUM5.4In "Xray Test Management for Jira" prior to version 3.5.5, remote authenticated attackers can cause XSS in the generic f...
CVE-2019-19645MEDIUM5.5alter.c in SQLite through 3.30.1 allows attackers to trigger infinite recursion via certain types of self-referential vi...
CVE-2019-16772MEDIUM6.1The serialize-to-js NPM package before version 3.0.1 is vulnerable to Cross-site Scripting (XSS). It does not properly m...
CVE-2019-9464MEDIUM5.5In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is ...
CVE-2019-2231MEDIUM4.4In Blob::Blob of blob.cpp, there is a possible unencrypted master key due to improper input validation. This could lead ...
CVE-2019-2229MEDIUM5.5In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. Thi...
CVE-2019-2228MEDIUM5.5In array_find of array.c, there is a possible out-of-bounds read due to an incorrect bounds check. This could lead to lo...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now