2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-10494HIGH8.1Race condition between the camera functions due to lack of resource lock which will lead to memory corruption and UAF is...
CVE-2019-10485HIGH7.5Infinite loop while decoding compressed data can lead to overrun condition in Snapdragon Auto, Snapdragon Compute, Snapd...
CVE-2019-19726HIGH7.8OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be...
CVE-2019-5154HIGH8.8An exploitable heap overflow vulnerability exists in the JPEG2000 parsing functionality of LEADTOOLS 20.0.2019.3.15. A s...
CVE-2019-5092HIGH8.8An exploitable heap out of bounds write vulnerability exists in the UI tag parsing functionality of the DICOM image form...
CVE-2019-5091HIGH7.5An exploitable denial-of-service vulnerability exists in the Dicom-packet parsing functionality of LEADTOOLS libltdic.so...
CVE-2019-5090HIGH7.5An exploitable information disclosure vulnerability exists in the DICOM packet-parsing functionality of LEADTOOLS libltd...
CVE-2019-3988HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3987HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3986HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-3985HIGH8.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-18245HIGH7.8Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into th...
CVE-2019-18232HIGH7.8SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulne...
CVE-2019-17087HIGH7.5Unauthorized file download vulnerability in all supported versions of Micro Focus AcuToWeb. The vulnerability could be e...
CVE-2019-0405HIGH7.5SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to con...
CVE-2019-0404HIGH7.5SAP Enable Now, before version 1911, leaks information about network configuration in the server error messages, leading...
CVE-2019-0398HIGH8.8Due to insufficient CSRF protection, SAP BusinessObjects Business Intelligence Platform (Monitoring Application), before...
CVE-2019-19729HIGH7.5An issue was discovered in the BSON ObjectID (aka bson-objectid) package 1.3.0 for Node.js. ObjectID() allows an attacke...
CVE-2019-19373HIGH7.5An issue was discovered in Squiz Matrix CMS 5.5.0 prior to 5.5.0.3, 5.5.1 prior to 5.5.1.8, 5.5.2 prior to 5.5.2.4, and ...
CVE-2019-19650HIGH8.8Zoho ManageEngine Applications Manager before 13640 allows a remote authenticated SQL injection via the Agent servlet ag...
CVE-2019-19583HIGH7.5An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS...
CVE-2019-19578HIGH8.8An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate...
CVE-2019-19577HIGH7.2An issue was discovered in Xen through 4.12.x allowing x86 AMD HVM guest OS users to cause a denial of service or possib...
CVE-2019-18379HIGH7.3Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which i...
CVE-2019-18377HIGH7.2Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now