CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-8503

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious website may be able to execute scripts in the context of another website.

    Published: 10 Apr 2019
    8.8
    High

    CVE-2019-8518

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 10 Apr 2019
    8.8
    High

    CVE-2019-8563

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 10 Apr 2019
    5.9
    Medium

    CVE-2019-9494

    Last Modified: 21 Nov 2024

    The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

    Published: 10 Apr 2019
    7.5
    High

    CVE-2019-9496

    Last Modified: 21 Nov 2024

    An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

    Published: 10 Apr 2019
    8.1
    High

    CVE-2019-9499

    Last Modified: 21 Nov 2024

    The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4 are affected. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.

    Published: 10 Apr 2019
    8.8
    High

    CVE-2019-8506

    Last Modified: 23 Oct 2025

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution.

    Published: 10 Apr 2019
    8.1
    High

    CVE-2019-0232

    Last Modified: 21 Nov 2024

    When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JRE behaviour, see Markus Wulftange's blog (https://codewhitesec.blogspot.com/2016/02/java-and-command-line-injections-in-windows.html) and this archived MSDN blog (https://web.archive.org/web/20161228144344/https://blogs.msdn.microsoft.com/twistylittlepassagesallalike/2011/04/23/everyone-quotes-command-line-arguments-the-wrong-way/).

    Published: 10 Apr 2019
    8.1
    High

    CVE-2019-1003049

    Last Modified: 21 Nov 2024

    Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.

    Published: 10 Apr 2019
    2.5
    Low

    CVE-2019-1573

    Last Modified: 21 Nov 2024

    GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow a local authenticated attacker who has compromised the end-user account and gained the ability to inspect memory, to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-5585

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in FortiClientMac before 6.0.5 may allow an attacker to affect the application's performance via modifying the contents of a file used by several FortiClientMac processes.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2018-1356

    Last Modified: 21 Nov 2024

    A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component.

    Published: 9 Apr 2019
    9.8
    Critical

    CVE-2019-6140

    Last Modified: 21 Nov 2024

    A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not completed.

    Published: 9 Apr 2019
    5.9
    Medium

    CVE-2019-8456

    Last Modified: 21 Nov 2024

    Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-9696

    Last Modified: 21 Nov 2024

    Symantec VIP Enterprise Gateway (all versions) may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0869

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0870

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0871.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0871

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0874

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0876

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0875

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists when Azure DevOps Server 2019 does not properly enforce project permissions, aka 'Azure DevOps Server Elevation of Privilege Vulnerability'.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0877

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0879.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0879

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0851, CVE-2019-0877.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0867

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0868, CVE-2019-0870, CVE-2019-0871.

    Published: 9 Apr 2019
    7.2
    High

    CVE-2019-0856

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0858

    Last Modified: 21 Nov 2024

    A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0866

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0867, CVE-2019-0868, CVE-2019-0870, CVE-2019-0871.

    Published: 9 Apr 2019
    6.5
    Medium

    CVE-2019-0857

    Last Modified: 21 Nov 2024

    A spoofing vulnerability that could allow a security feature bypass exists in when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Spoofing Vulnerability'.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0860

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0861.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0861

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0862

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0739, CVE-2019-0752, CVE-2019-0753.

    Published: 9 Apr 2019
    6.1
    Medium

    CVE-2019-0868

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0870, CVE-2019-0871.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0859

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

    Published: 9 Apr 2019
    8.8
    High

    CVE-2019-0853

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0847

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0844

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0840.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0846

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0847, CVE-2019-0851, CVE-2019-0877, CVE-2019-0879.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0848

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0814.

    Published: 9 Apr 2019
    8.8
    High

    CVE-2019-0842

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    6.5
    Medium

    CVE-2019-0849

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0802.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0851

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0846, CVE-2019-0847, CVE-2019-0877, CVE-2019-0879.

    Published: 9 Apr 2019
    4.4
    Medium

    CVE-2019-0839

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Terminal Services component improperly discloses the contents of its memory, aka 'Windows Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0838.

    Published: 9 Apr 2019
    5.5
    Medium

    CVE-2019-0840

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0844.

    Published: 9 Apr 2019
    8.8
    High

    CVE-2019-0845

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the IOleCvt interface renders ASP webpage content, aka 'Windows IOleCvt Interface Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0841

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0826

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0827.

    Published: 9 Apr 2019
    7.8
    High

    CVE-2019-0828

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.

    Published: 9 Apr 2019
    7.5
    High

    CVE-2019-0829

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0806, CVE-2019-0810, CVE-2019-0812, CVE-2019-0860, CVE-2019-0861.

    Published: 9 Apr 2019
    5.4
    Medium

    CVE-2019-0830

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-0831.

    Published: 9 Apr 2019
    5.4
    Medium

    CVE-2019-0831

    Last Modified: 28 Feb 2025

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-0830.

    Published: 9 Apr 2019