2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2232 | HIGH | 7.5 | 1.1% | Dec 6, 2019 | In handleRun of TextLine.java, there is a possible application crash due to improper input validation. This could lead t... |
| CVE-2019-2230 | HIGH | 7.5 | 0.8% | Dec 6, 2019 | In nfcManager_routeAid and nfcManager_unrouteAid of NativeNfcManager.cpp, there is possible memory reuse due to a use af... |
| CVE-2019-2225 | HIGH | 8.8 | 0.4% | Dec 6, 2019 | When pairing with a Bluetooth device, it may be possible to pair a malicious device without any confirmation from the us... |
| CVE-2019-2223 | HIGH | 7.8 | 0.6% | Dec 6, 2019 | In ihevcd_ref_list of ihevcd_ref_list.c, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2019-2222 | HIGH | 7.8 | 0.6% | Dec 6, 2019 | n ihevcd_parse_slice_data of ihevcd_parse_slice.c, there is a possible out of bounds write due to a missing bounds check... |
| CVE-2019-2221 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In hasActivityInVisibleTask of WindowProcessController.java there’s a possible bypass of user interaction requirements d... |
| CVE-2019-2218 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In createSessionInternal of PackageInstallerService.java, there is a possible improper permission grant due to a missing... |
| CVE-2019-2217 | HIGH | 7.8 | 0.2% | Dec 6, 2019 | In setCpuVulkanInUse of GpuStats.cpp, there is possible memory corruption due to a use after free. This could lead to lo... |
| CVE-2019-18575 | HIGH | 7.1 | 0.3% | Dec 6, 2019 | Dell Command Configure versions prior to 4.2.1 contain an uncontrolled search path vulnerability. A locally authenticate... |
| CVE-2019-18672 | HIGH | 7.5 | 0.8% | Dec 6, 2019 | Insufficient checks in the finite state machine of the ShapeShift KeepKey hardware wallet before firmware 6.2.2 allow a ... |
| CVE-2019-12734 | HIGH | 8.8 | 2.1% | Dec 6, 2019 | SiteVision 4 has Incorrect Access Control. |
| CVE-2019-12733 | HIGH | 8.8 | 6.0% | Dec 6, 2019 | SiteVision 4 allows Remote Code Execution. |
| CVE-2019-19609 | HIGH | 7.2 | 54.1% | Dec 5, 2019 | The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c... |
| CVE-2019-16770 | HIGH | 7.5 | 1.9% | Dec 5, 2019 | In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reac... |
| CVE-2019-5098 | HIGH | 8.6 | 2.0% | Dec 5, 2019 | An exploitable out-of-bounds read vulnerability exists in AMD ATIDXX64.DLL driver, version 26.20.13001.29010. A speciall... |
| CVE-2019-17388 | HIGH | 7.8 | 0.6% | Dec 5, 2019 | Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allo... |
| CVE-2019-17387 | HIGH | 7.8 | 0.7% | Dec 5, 2019 | An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated... |
| CVE-2019-3690 | HIGH | 7.8 | 0.4% | Dec 5, 2019 | The chkstat tool in the permissions package followed symlinks before commit a9e1d26cd49ef9ee0c2060c859321128a6dd4230 (pl... |
| CVE-2019-19007 | HIGH | 7.2 | 1.6% | Dec 5, 2019 | Intelbras IWR 3000N 1.8.7 devices allow disclosure of the administrator login name and password because v1/system/user i... |
| CVE-2019-18180 | HIGH | 7.5 | 1.9% | Dec 5, 2019 | Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g. attac... |
| CVE-2019-17437 | HIGH | 7.8 | 0.3% | Dec 5, 2019 | An improper authentication check in Palo Alto Networks PAN-OS may allow an authenticated low privileged non-superuser cu... |
| CVE-2019-19601 | HIGH | 7.8 | 1.2% | Dec 5, 2019 | OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf. |
| CVE-2019-19598 | HIGH | 8.8 | 3.2% | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP... |
| CVE-2019-19597 | HIGH | 8.8 | 19.1% | Dec 5, 2019 | D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via sh... |
| CVE-2019-19590 | HIGH | 7.8 | 2.5% | Dec 5, 2019 | In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now