2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10494 | HIGH | 8.1 | 0.3% | Dec 12, 2019 | Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is... |
| CVE-2019-10485 | HIGH | 7.5 | 0.7% | Dec 12, 2019 | Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd... |
| CVE-2019-19726 | HIGH | 7.8 | 3.5% | Dec 12, 2019 | OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be... |
| CVE-2019-5154 | HIGH | 8.8 | 2.6% | Dec 12, 2019 | An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A s... |
| CVE-2019-5092 | HIGH | 8.8 | 2.5% | Dec 12, 2019 | An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image form... |
| CVE-2019-5091 | HIGH | 7.5 | 1.9% | Dec 12, 2019 | An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so... |
| CVE-2019-5090 | HIGH | 7.5 | 2.3% | Dec 12, 2019 | An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltd... |
| CVE-2019-3988 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3987 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3986 | HIGH | 8.8 | 1.2% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-3985 | HIGH | 8.8 | 1.7% | Dec 11, 2019 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ... |
| CVE-2019-18245 | HIGH | 7.8 | 0.4% | Dec 11, 2019 | Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th... |
| CVE-2019-18232 | HIGH | 7.8 | 0.4% | Dec 11, 2019 | SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulne... |
| CVE-2019-17087 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be e... |
| CVE-2019-0405 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con... |
| CVE-2019-0404 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading... |
| CVE-2019-0398 | HIGH | 8.8 | 0.5% | Dec 11, 2019 | Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before... |
| CVE-2019-19729 | HIGH | 7.5 | 1.1% | Dec 11, 2019 | An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacke... |
| CVE-2019-19373 | HIGH | 7.5 | 4.8% | Dec 11, 2019 | An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and ... |
| CVE-2019-19650 | HIGH | 8.8 | 5.7% | Dec 11, 2019 | Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet ag... |
| CVE-2019-19583 | HIGH | 7.5 | 2.2% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS... |
| CVE-2019-19578 | HIGH | 8.8 | 0.4% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate... |
| CVE-2019-19577 | HIGH | 7.2 | 0.5% | Dec 11, 2019 | An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possib... |
| CVE-2019-18379 | HIGH | 7.3 | 1.1% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which i... |
| CVE-2019-18377 | HIGH | 7.2 | 1.4% | Dec 11, 2019 | Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now