2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19643HIGH7.5ise smart connect KNX Vaillant 1.2.839 contain a Denial of Service.
CVE-2019-7410MEDIUM6.1There is stored cross site scripting (XSS) in Galileo CMS v0.042. Remote authenticated users could inject arbitrary web ...
CVE-2019-6112MEDIUM6.1A Cross-site scripting (XSS) vulnerability in /inc/class-search.php in the Sell Media plugin v2.4.1 for WordPress allows...
CVE-2019-20383HIGH7.8ABBYY network license server in ABBYY FineReader 15 before Release 4 (aka 15.0.112.2130) allows escalation of privileges...
CVE-2019-16374CRITICAL9.8Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. A...
CVE-2019-4582MEDIUM4.3IBM Maximo Asset Management 7.6.0 and 7.6.1 could allow a remote attacker to traverse directories on the system. An atta...
CVE-2019-14620MEDIUM6.5Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to ...
CVE-2019-14630MEDIUM4.6Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticat...
CVE-2019-17339HIGH8.1The VirtualRouter component of TIBCO Software Inc.'s TIBCO Silver Fabric contains a vulnerability that theoretically all...
CVE-2019-19704HIGH7.5In JetBrains Upsource before 2020.1, information disclosure is possible because of an incorrect user matching algorithm.
CVE-2019-7005HIGH7.5A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthen...
CVE-2019-20001HIGH7.8An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to es...
CVE-2019-19455HIGH7.8Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in ...
CVE-2019-19453MEDIUM5.4Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license e...
CVE-2019-4589MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 is vulnerable to privlege escalation where the "My schedules and subscriptions" page ...
CVE-2019-4366MEDIUM5.3IBM Cognos Analytics 11.0 and 11.1 is susceptible to an information disclosure vulnerability where an attacker could gai...
CVE-2019-11286CRITICAL9.1VMware GemFire versions prior to 9.10.0, 9.9.1, 9.8.5, and 9.7.5, and VMware Tanzu GemFire for VMs versions prior to 1.1...
CVE-2019-14130HIGH7.8Memory corruption can occurs in trusted application if offset size from HLOS is more than actual mapped buffer size in S...
CVE-2019-14124HIGH7.8Memory failure in content protection module due to not having pointer within the scope in Snapdragon Auto, Snapdragon Co...
CVE-2019-14123HIGH7.8Possible buffer overflow and over read possible due to missing bounds checks for fixed limits if we consider widevine HL...
CVE-2019-14101HIGH7.1Out of bounds read can happen in diag event set mask command handler when user provided length in the command request is...
CVE-2019-14100HIGH7.8Register write via debugfs is disabled by default to prevent register writing via debugfs. in Snapdragon Auto, Snapdrago...
CVE-2019-14099HIGH7.8Device misbehavior may be observed when incorrect offset, length or number of buffers is passed by user space in Snapdra...
CVE-2019-14093HIGH7.8Array out of bound access can occur in display module due to lack of bound check on input parcel received in Snapdragon ...
CVE-2019-14037HIGH7.8Close and bind operations done on a socket can lead to a Use-After-Free condition. in Snapdragon Auto, Snapdragon Comput...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now