2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-15291An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB...
CVE-2019-15290Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of ...
CVE-2019-15082The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS.
CVE-2019-14687A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...
CVE-2019-14684A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker...
CVE-2019-14430plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
CVE-2019-11806OX App Suite 7.10.1 and earlier has Insecure Permissions.
CVE-2019-11522OX App Suite 7.10.0 to 7.10.2 allows XSS.
CVE-2019-11521OX App Suite 7.10.1 allows Content Spoofing.
CVE-2019-12889An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only...
CVE-2019-15239In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrect...
CVE-2019-15227FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead t...
CVE-2019-15231Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of ...
CVE-2019-15229FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker...
CVE-2019-15228FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m...
CVE-2019-15225In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression...
CVE-2019-15224The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor i...
CVE-2019-11163Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows b...
CVE-2019-11162Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before ver...
CVE-2019-11148Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticate...
CVE-2019-11146Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote...
CVE-2019-11143Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to p...
CVE-2019-11140Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es...
CVE-2019-0173Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attac...
CVE-2019-15160The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now