2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-15291 | — | — | 0.7% | Aug 20, 2019 | An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB... |
| CVE-2019-15290 | — | — | — | Aug 20, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15098. Reason: This candidate is a duplicate of ... |
| CVE-2019-15082 | — | — | 0.9% | Aug 20, 2019 | The 360-product-rotation plugin before 1.4.8 for WordPress has reflected XSS. |
| CVE-2019-14687 | — | — | 1.6% | Aug 20, 2019 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker... |
| CVE-2019-14684 | — | — | 1.5% | Aug 20, 2019 | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker... |
| CVE-2019-14430 | — | — | 3.0% | Aug 20, 2019 | plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. |
| CVE-2019-11806 | — | — | 0.4% | Aug 20, 2019 | OX App Suite 7.10.1 and earlier has Insecure Permissions. |
| CVE-2019-11522 | — | — | 0.7% | Aug 20, 2019 | OX App Suite 7.10.0 to 7.10.2 allows XSS. |
| CVE-2019-11521 | — | — | 1.7% | Aug 20, 2019 | OX App Suite 7.10.1 allows Content Spoofing. |
| CVE-2019-12889 | — | — | 0.6% | Aug 20, 2019 | An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only... |
| CVE-2019-15239 | — | — | 0.6% | Aug 20, 2019 | In the Linux kernel, a certain net/ipv4/tcp_output.c change, which was properly incorporated into 4.16.12, was incorrect... |
| CVE-2019-15227 | — | — | 0.8% | Aug 20, 2019 | FlightPath 4.8.3 has XSS in the Content, Edit urgent message, and Users sections of the Admin Console. This could lead t... |
| CVE-2019-15231 | — | — | — | Aug 20, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-15107. Reason: This candidate is a duplicate of ... |
| CVE-2019-15229 | — | — | 0.7% | Aug 20, 2019 | FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker... |
| CVE-2019-15228 | — | — | 0.7% | Aug 20, 2019 | FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other m... |
| CVE-2019-15225 | — | — | 3.4% | Aug 19, 2019 | In Envoy through 1.11.1, users may configure a route to match incoming path headers via the libstdc++ regular expression... |
| CVE-2019-15224 | — | — | 3.5% | Aug 19, 2019 | The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor i... |
| CVE-2019-11163 | — | — | 0.4% | Aug 19, 2019 | Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows b... |
| CVE-2019-11162 | — | — | 0.4% | Aug 19, 2019 | Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before ver... |
| CVE-2019-11148 | — | — | 0.3% | Aug 19, 2019 | Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticate... |
| CVE-2019-11146 | — | — | 0.3% | Aug 19, 2019 | Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to pote... |
| CVE-2019-11143 | — | — | 0.4% | Aug 19, 2019 | Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to p... |
| CVE-2019-11140 | — | — | 0.4% | Aug 19, 2019 | Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable es... |
| CVE-2019-0173 | — | — | 0.8% | Aug 19, 2019 | Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attac... |
| CVE-2019-15160 | — | — | 1.7% | Aug 19, 2019 | The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to cause a denial of service (... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now