2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-13666HIGH7.4Information leak in storage in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data v...
CVE-2019-18675HIGH7.8The Linux kernel through 5.3.13 has a start_offset+size Integer Overflow in cpia2_remap_buffer in drivers/media/usb/cpia...
CVE-2019-14822HIGH7.1A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method cal...
CVE-2019-14815HIGH7.8A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marve...
CVE-2019-10174HIGH8.8A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allow...
CVE-2019-11287HIGH7.5Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x ver...
CVE-2019-18909HIGH8The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to ...
CVE-2019-3654HIGH8.6Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows l...
CVE-2019-18610HIGH8.8An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 1...
CVE-2019-17446HIGH7.8An issue was discovered in Eracent EPA Agent through 10.2.26. The agent executable, when installed for non-root operatio...
CVE-2019-18976HIGH7.5An issue was discovered in res_pjsip_t38.c in Sangoma Asterisk through 13.x and Certified Asterisk through 13.21-x. If i...
CVE-2019-3427HIGH7.2The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exp...
CVE-2019-19013HIGH8.8A CSRF vulnerability in Pagekit 1.0.17 allows an attacker to upload an arbitrary file by removing the CSRF token from a ...
CVE-2019-13157HIGH7.5nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences...
CVE-2019-18888HIGH7.5An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4...
CVE-2019-18887HIGH8.1An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4...
CVE-2019-19207HIGH8.8rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
CVE-2019-19204HIGH7.5An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as ...
CVE-2019-19203HIGH7.5An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UCha...
CVE-2019-5637HIGH7.5When Beckhoff TwinCAT is configured to use the Profinet driver, a denial of service of the controller could be reached b...
CVE-2019-5636HIGH7.5When a Beckhoff TwinCAT Runtime receives a malformed UDP packet, the ADS Discovery Service shuts down. Note that the Twi...
CVE-2019-19202HIGH8.8In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to c...
CVE-2019-19197HIGH7.8IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escala...
CVE-2019-19191HIGH7.8Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlle...
CVE-2019-16758HIGH7.5In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now