2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20029HIGH8.8An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, includ...
CVE-2019-20028HIGH7.5Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices ...
CVE-2019-20027CRITICAL9.8Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain t...
CVE-2019-20026HIGH7.5The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all ...
CVE-2019-20025CRITICAL9.8Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an af...
CVE-2019-4731MEDIUM5.5IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive ...
CVE-2019-18834MEDIUM6.1Persistent XSS in the WooCommerce Subscriptions plugin before 2.6.3 for WordPress allows remote attackers to execute arb...
CVE-2019-11252MEDIUM6.5The Kubernetes kube-controller-manager in versions v1.0-v1.17 is vulnerable to a credential leakage via error messages i...
CVE-2019-16244CRITICAL9.8OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CVE-2019-18619HIGH7.8Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prio...
CVE-2019-18618MEDIUM6Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (al...
CVE-2019-12000MEDIUM6.6HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when...
CVE-2019-4091MEDIUM5.4"HCL Marketing Platform is vulnerable to cross-site scripting during addition of new users and also while searching for ...
CVE-2019-4090MEDIUM5.4"HCL Campaign is vulnerable to cross-site scripting when a user provides XSS scripts in Campaign Description field."
CVE-2019-20915HIGH8.1An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_w...
CVE-2019-20914CRITICAL9.8An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_co...
CVE-2019-20913HIGH8.1An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_e...
CVE-2019-20912HIGH8.8An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly r...
CVE-2019-20911MEDIUM6.5An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in b...
CVE-2019-20910HIGH8.1An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decod...
CVE-2019-20909HIGH7.5An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LW...
CVE-2019-4748MEDIUM5.4IBM Jazz Team Server based Applications are vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2019-4747MEDIUM5.4IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScr...
CVE-2019-20908MEDIUM6.7An issue was discovered in drivers/firmware/efi/efi.c in the Linux kernel before 5.4. Incorrect access permissions for t...
CVE-2019-17639MEDIUM5.3In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer tha...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now