2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-17237HIGH8.8includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
CVE-2019-17234HIGH7.5includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary...
CVE-2019-4652HIGH7.1IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Wind...
CVE-2019-18848HIGH7.5The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
CVE-2019-18817HIGH7.5Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related...
CVE-2019-18874HIGH7.5psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a wh...
CVE-2019-18862HIGH7.8maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
CVE-2019-18857HIGH7.5darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected w...
CVE-2019-18856HIGH7.5A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to...
CVE-2019-18855HIGH7.5A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to p...
CVE-2019-18854HIGH7.5A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to u...
CVE-2019-18841HIGH7.3Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.
CVE-2019-18836HIGH7.5Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connectio...
CVE-2019-18845HIGH7.1The MsIo64.sys and MsIo32.sys drivers in Patriot Viper RGB before 1.1 allow local users (including low integrity process...
CVE-2019-18840HIGH7.5In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data wh...
CVE-2019-5701HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in whic...
CVE-2019-5697HIGH7.1NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which it may grant a guest access to memory that i...
CVE-2019-5692HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle...
CVE-2019-5691HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle...
CVE-2019-5690HIGH7.8NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handle...
CVE-2019-5689HIGH7.8NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a...
CVE-2019-13543HIGH7.5Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4...
CVE-2019-13539HIGH7.8Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4...
CVE-2019-3426HIGH8.8The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by the input validation vul...
CVE-2019-3425HIGH8.8The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permiss...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now