2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19100HIGH7.1A privilege escalation vulnerability in the upgrade service in B&R Automation Studio versions 4.0.x, 4.1.x, 4.2.x, < 4.3...
CVE-2019-5614CRITICAL9.8In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE...
CVE-2019-15874CRITICAL9.8In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE...
CVE-2019-15877MEDIUM5.5In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in...
CVE-2019-15876MEDIUM5.5In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE...
CVE-2019-20791CRITICAL9.8OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.
CVE-2019-15790LOW3.3Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines w...
CVE-2019-5303MEDIUM5.3There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC...
CVE-2019-5302MEDIUM5.3There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SC...
CVE-2019-15234HIGH7.5SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to alloc...
CVE-2019-14941HIGH7.5SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memo...
CVE-2019-20002HIGH7.8Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privilege...
CVE-2019-18823CRITICAL9.8HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possib...
CVE-2019-4729MEDIUM4.3IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to obtain sensitive information when a detailed technic...
CVE-2019-20790CRITICAL9.8OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authenti...
CVE-2019-18223MEDIUM5.4ZOOM International Call Recording 6.3.1 suffers from multiple authenticated stored XSS vulnerabilities via the phoneNumb...
CVE-2019-20789MEDIUM4.8Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
CVE-2019-4751MEDIUM5.3IBM Cloud App Management 2019.3.0 and 2019.4.0 reveals a stack trace on certain API requests which can allow an attacker...
CVE-2019-4750HIGH8.8IBM Cloud App Management 2019.3.0 and 2019.4.0 is vulnerable to cross-site request forgery which could allow an attacker...
CVE-2019-15794MEDIUM6.7Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 k...
CVE-2019-15793HIGH8.8In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations...
CVE-2019-15792HIGH7.8In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioc...
CVE-2019-15791HIGH7.8In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioc...
CVE-2019-20788CRITICAL9.8libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer over...
CVE-2019-17101MEDIUM6.7Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in firmware versions p...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now