2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2227 | MEDIUM | 6.5 | 0.3% | Dec 6, 2019 | In DeepCopy of btif_av.cc, there is a possible out of bounds read due to improper casting. This could lead to remote inf... |
| CVE-2019-2226 | MEDIUM | 5.5 | 0.1% | Dec 6, 2019 | In device_class_to_int of device_class.cc, there is a possible out of bounds read due to improper casting. This could le... |
| CVE-2019-2220 | MEDIUM | 5.5 | 0.2% | Dec 6, 2019 | In checkOperation of AppOpsService.java, there is a possible bypass of user interaction requirements due to mishandling ... |
| CVE-2019-2219 | MEDIUM | 4.7 | 0.1% | Dec 6, 2019 | In several functions of NotificationManagerService.java and related files, there is a possible way to record audio from ... |
| CVE-2019-11293 | MEDIUM | 6.5 | 1.3% | Dec 6, 2019 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials w... |
| CVE-2019-16771 | MEDIUM | 6.5 | 1.0% | Dec 6, 2019 | Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote a... |
| CVE-2019-1551 | MEDIUM | 5.3 | 14.3% | Dec 6, 2019 | There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC a... |
| CVE-2019-16673 | MEDIUM | 6.5 | 1.1% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-16671 | MEDIUM | 6.5 | 1.9% | Dec 6, 2019 | An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL... |
| CVE-2019-19627 | MEDIUM | 5.3 | 2.1% | Dec 6, 2019 | SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_... |
| CVE-2019-19625 | MEDIUM | 5.3 | 1.5% | Dec 6, 2019 | SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the under... |
| CVE-2019-19552 | MEDIUM | 4.8 | 0.6% | Dec 6, 2019 | In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator ... |
| CVE-2019-19551 | MEDIUM | 4.8 | 0.6% | Dec 6, 2019 | In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator ... |
| CVE-2019-11554 | MEDIUM | 5.9 | 0.5% | Dec 6, 2019 | The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM ... |
| CVE-2019-19624 | MEDIUM | 6.5 | 1.7% | Dec 6, 2019 | An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be grea... |
| CVE-2019-19619 | MEDIUM | 6.1 | 1.2% | Dec 6, 2019 | domain/section/markdown/markdown.go in Documize before 3.5.1 mishandles untrusted Markdown content. This was addressed b... |
| CVE-2019-19616 | MEDIUM | 4.3 | 0.7% | Dec 6, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for M... |
| CVE-2019-16768 | MEDIUM | 4.3 | 0.7% | Dec 5, 2019 | In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Sy... |
| CVE-2019-16769 | MEDIUM | 5.4 | 1.0% | Dec 5, 2019 | The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not prope... |
| CVE-2019-19546 | MEDIUM | 6.5 | 0.9% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vul... |
| CVE-2019-19545 | MEDIUM | 6.3 | 0.3% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w... |
| CVE-2019-18381 | MEDIUM | 6.3 | 0.3% | Dec 5, 2019 | Norton Password Manager, prior to 6.6.2.5, may be susceptible to a cross origin resource sharing (CORS) vulnerability, w... |
| CVE-2019-7185 | MEDIUM | 4.8 | 1.5% | Dec 5, 2019 | This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on ... |
| CVE-2019-7184 | MEDIUM | 4.8 | 1.5% | Dec 5, 2019 | This cross-site scripting (XSS) vulnerability in Video Station allows remote attackers to inject and execute scripts on ... |
| CVE-2019-19466 | MEDIUM | 6.1 | 0.7% | Dec 5, 2019 | SCEditor 2.1.3 allows XSS. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now