2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-8127HIGH8.8A SQL injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenti...
CVE-2019-8125HIGH7.2A remote code execution vulnerability exists in Magento 1 prior to 1.9.x and 1.14.x. An authenticated admin user can mod...
CVE-2019-8122HIGH8.8A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 pr...
CVE-2019-8119HIGH7.2A remote code execution vulnerability exists in Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 pr...
CVE-2019-8116HIGH7.5Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to...
CVE-2019-8114HIGH7.2A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3, Magento 2.2 prior to 2.2.10, Ma...
CVE-2019-8112HIGH7.5A security bypass vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauth...
CVE-2019-8111HIGH8.8A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ...
CVE-2019-8110HIGH8.8A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ...
CVE-2019-8109HIGH8A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An ...
CVE-2019-8093HIGH8.8An arbitrary file access vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An...
CVE-2019-8091HIGH7.2A remote code execution vulnerability exists in Magento 1 prior to 1.9.4.3 and 1.14.4.3. An authenticated admin user wit...
CVE-2019-5089HIGH7.8An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially c...
CVE-2019-5088HIGH7.8An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially ...
CVE-2019-16284HIGH7.2A potential security vulnerability has been identified in multiple HP products and versions which involves possible exec...
CVE-2019-10084HIGH7.5In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can i...
CVE-2019-1789HIGH7.5ClamAV versions prior to 0.101.2 are susceptible to a denial of service (DoS) vulnerability. An out-of-bounds heap read ...
CVE-2019-15966HIGH7.7A vulnerability in the web application of Cisco TelePresence Advanced Media Gateway could allow an authenticated, remote...
CVE-2019-12625HIGH7.5ClamAV versions prior to 0.101.3 are susceptible to a zip bomb vulnerability where an unauthenticated attacker can cause...
CVE-2019-18631HIGH7.8The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5...
CVE-2019-17062HIGH8.8An issue was discovered in OXID eShop 6.x before 6.0.6 and 6.1.x before 6.1.5, OXID eShop Enterprise Edition Version 5.2...
CVE-2019-17598HIGH7.5An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an auth...
CVE-2019-17221HIGH7.5PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI...
CVE-2019-3685HIGH7.7Open Build Service before version 0.165.4 diddn't validate TLS certificates for HTTPS connections with the osc client bi...
CVE-2019-18178HIGH7.5Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now