2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13734 | HIGH | 8.8 | 4.0% | Dec 10, 2019 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit he... |
| CVE-2019-13732 | HIGH | 8.8 | 1.3% | Dec 10, 2019 | Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap ... |
| CVE-2019-13730 | HIGH | 8.8 | 1.9% | Dec 10, 2019 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-13729 | HIGH | 8.8 | 1.5% | Dec 10, 2019 | Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit hea... |
| CVE-2019-13728 | HIGH | 8.8 | 1.6% | Dec 10, 2019 | Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploi... |
| CVE-2019-13727 | HIGH | 8.8 | 1.4% | Dec 10, 2019 | Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass... |
| CVE-2019-13726 | HIGH | 8.8 | 2.2% | Dec 10, 2019 | Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrar... |
| CVE-2019-13725 | HIGH | 8.8 | 2.0% | Dec 10, 2019 | Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code v... |
| CVE-2019-5843 | HIGH | 8.8 | 0.8% | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potential... |
| CVE-2019-5841 | HIGH | 8.8 | 0.8% | Dec 10, 2019 | Out of bounds memory access in JavaScript in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentiall... |
| CVE-2019-19702 | HIGH | 7.5 | 1.5% | Dec 10, 2019 | The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processin... |
| CVE-2019-6183 | HIGH | 7.5 | 1.9% | Dec 10, 2019 | A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to ... |
| CVE-2019-4612 | HIGH | 8.8 | 1.0% | Dec 9, 2019 | IBM Planning Analytics 2.0 is vulnerable to malicious file upload in the My Account Portal. Attackers can make use of th... |
| CVE-2019-19603 | HIGH | 7.5 | 8.3% | Dec 9, 2019 | SQLite 3.30.1 mishandles certain SELECT statements with a nonexistent VIEW, leading to an application crash. |
| CVE-2019-19687 | HIGH | 8.8 | 1.8% | Dec 9, 2019 | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a ... |
| CVE-2019-19685 | HIGH | 8.8 | 0.5% | Dec 9, 2019 | RoxyFileman, as shipped with nopCommerce v4.2.0, is vulnerable to CSRF because GET requests can be used for renames and ... |
| CVE-2019-19684 | HIGH | 8.8 | 1.6% | Dec 9, 2019 | nopCommerce v4.2.0 allows privilege escalation via file upload in Presentation/Nop.Web/Admin/Areas/Controllers/PluginCon... |
| CVE-2019-14251 | HIGH | 7.5 | 7.8% | Dec 9, 2019 | An issue was discovered in T24 in TEMENOS Channels R15.01. The login page presents JavaScript functions to access a docu... |
| CVE-2019-19648 | HIGH | 7.8 | 1.6% | Dec 9, 2019 | In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real si... |
| CVE-2019-19647 | HIGH | 7.8 | 1.6% | Dec 9, 2019 | radare2 through 4.0.0 lacks validation of the content variable in the function r_asm_pseudo_incbin at libr/asm/asm.c, ul... |
| CVE-2019-19642 | HIGH | 8.8 | 19.0% | Dec 8, 2019 | On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command I... |
| CVE-2019-19630 | HIGH | 7.8 | 1.1% | Dec 8, 2019 | HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_con... |
| CVE-2019-19449 | HIGH | 7.8 | 2.0% | Dec 8, 2019 | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_... |
| CVE-2019-19448 | HIGH | 7.8 | 2.2% | Dec 8, 2019 | In the Linux kernel 5.0.21 and 5.3.11, mounting a crafted btrfs filesystem image, performing some operations, and then m... |
| CVE-2019-19447 | HIGH | 7.8 | 3.5% | Dec 8, 2019 | In the Linux kernel 5.0.21, mounting a crafted ext4 filesystem image, performing some operations, and unmounting can lea... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now