2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4715 | HIGH | 8.8 | 4.0% | Dec 11, 2019 | IBM Spectrum Scale 4.2 and 5.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. ... |
| CVE-2019-14899 | HIGH | 7.4 | 0.8% | Dec 11, 2019 | A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point,... |
| CVE-2019-3667 | HIGH | 7.8 | 0.3% | Dec 11, 2019 | DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allow... |
| CVE-2019-19720 | HIGH | 8.8 | 1.2% | Dec 11, 2019 | Yabasic 2.86.1 has a heap-based buffer overflow in the yylex() function in flex.c via a crafted BASIC source file. |
| CVE-2019-19707 | HIGH | 7.5 | 1.2% | Dec 11, 2019 | On Moxa EDS-G508E, EDS-G512E, and EDS-G516E devices (with firmware through 6.0), denial of service can occur via PROFINE... |
| CVE-2019-5815 | HIGH | 7.5 | 1.7% | Dec 11, 2019 | Type confusion in xsltNumberFormatGetMultipleLevel prior to libxslt 1.1.33 could allow attackers to potentially exploit ... |
| CVE-2019-19604 | HIGH | 7.8 | 3.7% | Dec 11, 2019 | Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before ... |
| CVE-2019-14889 | HIGH | 8.8 | 3.2% | Dec 10, 2019 | A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh S... |
| CVE-2019-1489 | HIGH | 7.5 | 7.7% | Dec 10, 2019 | An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle o... |
| CVE-2019-1485 | HIGH | 7.5 | 7.7% | Dec 10, 2019 | A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScrip... |
| CVE-2019-1484 | HIGH | 7.8 | 8.9% | Dec 10, 2019 | A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Wind... |
| CVE-2019-1483 | HIGH | 7.8 | 1.8% | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e... |
| CVE-2019-1478 | HIGH | 7.8 | 0.8% | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Ser... |
| CVE-2019-1477 | HIGH | 7.8 | 1.0% | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows Printer Service improperly validates file paths while lo... |
| CVE-2019-1476 | HIGH | 7.8 | 5.1% | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li... |
| CVE-2019-1471 | HIGH | 8.2 | 8.1% | Dec 10, 2019 | A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from... |
| CVE-2019-1468 | HIGH | 8.8 | 16.6% | Dec 10, 2019 | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded... |
| CVE-2019-1462 | HIGH | 7.8 | 18.3% | Dec 10, 2019 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle... |
| CVE-2019-1458 | HIGH | 7.8 | 73.9% | Dec 10, 2019 | An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in ... |
| CVE-2019-1453 | HIGH | 7.5 | 9.2% | Dec 10, 2019 | A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system... |
| CVE-2019-13764 | HIGH | 8.8 | 6.4% | Dec 10, 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-13747 | HIGH | 8.8 | 1.3% | Dec 10, 2019 | Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potential... |
| CVE-2019-13741 | HIGH | 8.8 | 1.1% | Dec 10, 2019 | Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to b... |
| CVE-2019-13736 | HIGH | 8.8 | 1.5% | Dec 10, 2019 | Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap ... |
| CVE-2019-13735 | HIGH | 8.8 | 1.8% | Dec 10, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now