7.8
    High

    CVE-2019-6218

    Last Modified: 31 Jan 2019

    A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may be able to execute arbitrary code with kernel privileges.

    Source:Google Security Research
    Published:5 Mar 2019
    8.8
    High

    CVE-2019-6215

    Last Modified: 22 Feb 2019

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safari 12.0.3, iTunes 12.9.3 for Windows, iCloud for Windows 7.10. Processing maliciously crafted web content may lead to arbitrary code execution.

    Source:Google Security Research
    Published:5 Mar 2019
    8.6
    High

    CVE-2019-6214

    Last Modified: 31 Jan 2019

    A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to break out of its sandbox.

    Source:Google Security Research
    Published:5 Mar 2019
    7.8
    High

    CVE-2019-6213

    Last Modified: 31 Jan 2019

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. An application may be able to execute arbitrary code with kernel privileges.

    Source:Google Security Research
    Published:5 Mar 2019
    5.5
    Medium

    CVE-2019-6209

    Last Modified: 30 Jan 2019

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2, watchOS 5.1.3. A malicious application may be able to determine kernel memory layout.

    Source:Google Security Research
    Published:5 Mar 2019
    5.5
    Medium

    CVE-2019-6208

    Last Modified: 31 Jan 2019

    A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

    Source:Google Security Research
    Published:5 Mar 2019
    5.5
    Medium

    CVE-2019-6207

    Last Modified: 21 Nov 2024

    An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2. A malicious application may be able to determine kernel memory layout.

    Published:18 Dec 2019
    7.8
    High

    CVE-2019-6205

    Last Modified: 31 Jan 2019

    A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3, tvOS 12.1.2. A malicious application may cause unexpected changes in memory shared between processes.

    Source:Google Security Research
    Published:5 Mar 2019
    9.8
    Critical

    CVE-2019-6203

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.

    Published:17 Apr 2020
    4.4
    Medium

    CVE-2019-6192

    Last Modified: 12 Dec 2019

    A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a buffer overflow which could cause a denial of service.

    Source:Nassim Asrir
    Published:10 Dec 2019
    6.1
    Medium

    CVE-2019-6146

    Last Modified: 10 Feb 2020

    It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

    Source:Prasenjit Kanti Paul
    Published:22 Jan 2020
    7.8
    High

    CVE-2019-6116

    Last Modified: 24 Jan 2019

    In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.

    Source:Google Security Research
    Published:23 Jan 2019
    5.9
    Medium

    CVE-2019-6111

    Last Modified: 7 Mar 2019

    An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

    Source:Harry Sintonen
    Published:16 Nov 2018
    6.8
    Medium

    CVE-2019-6110

    Last Modified: 7 Mar 2019

    In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

    Source:Harry Sintonen
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2019-5893

    Last Modified: 10 Jan 2019

    Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter.

    Source:Emre ÖVÜNÇ
    Published:10 Jan 2019
    6.5
    Medium

    CVE-2019-5825

    Last Modified: 9 Mar 2020

    Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Metasploit
    Published:30 Apr 2019
    8.8
    High

    CVE-2019-5822

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published:23 Apr 2019
    7.5
    High

    CVE-2019-5797

    Last Modified: 19 Mar 2019

    Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Google Security Research
    Published:12 Mar 2019
    7.5
    High

    CVE-2019-5796

    Last Modified: 19 Mar 2019

    Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Google Security Research
    Published:12 Mar 2019
    8.8
    High

    CVE-2019-5789

    Last Modified: 19 Mar 2019

    An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

    Source:Google Security Research
    Published:12 Mar 2019
    8.8
    High

    CVE-2019-5788

    Last Modified: 19 Mar 2019

    An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page.

    Source:Google Security Research
    Published:12 Mar 2019
    6.5
    Medium

    CVE-2019-5786

    Last Modified: 8 May 2019

    Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Source:Metasploit
    Published:1 Mar 2019
    6.5
    Medium

    CVE-2019-5784

    Last Modified: 21 Nov 2024

    Incorrect handling of deferred code in V8 in Google Chrome prior to 72.0.3626.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published:6 Feb 2019
    8.8
    High

    CVE-2019-5782

    Last Modified: 21 Nov 2024

    Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published:29 Jan 2019
    7.5
    High

    CVE-2019-5737

    Last Modified: 21 Nov 2024

    In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or HTTPS connection in keep-alive mode and by sending headers very slowly. This keeps the connection and associated resources alive for a long period of time. Potential attacks are mitigated by the use of a load balancer or other proxy layer. This vulnerability is an extension of CVE-2018-12121, addressed in November and impacts all active Node.js release lines including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1.

    Published:28 Feb 2019
    8.6
    High

    CVE-2019-5736

    Last Modified: 14 Feb 2019

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

    Source:feexd
    Published:11 Feb 2019
    9.8
    Critical

    CVE-2019-5722

    Last Modified: 14 Jan 2019

    An issue was discovered in portier vision 4.4.4.2 and 4.4.4.6. Due to a lack of user input validation in parameter handling, it has various SQL injections, including on the login form, and on the search form for a key ring number.

    Source:SySS GmbH
    Published:19 Mar 2019
    7.8
    High

    CVE-2019-5700

    Last Modified: 21 Nov 2024

    NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

    Published:9 Oct 2019
    6.7
    Medium

    CVE-2019-5688

    Last Modified: 21 Nov 2024

    NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service.

    Published:18 Nov 2019
    5.9
    Medium

    CVE-2019-5630

    Last Modified: 21 Nov 2024

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.

    Published:3 Jul 2019
    7.3
    High

    CVE-2019-5624

    Last Modified: 21 Nov 2024

    Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at the privilege level of the user running Metasploit. This issue affects: Rapid7 Metasploit Framework version 4.14.0 and prior versions.

    Published:30 Apr 2019
    7.8
    High

    CVE-2019-5603

    Last Modified: 21 Nov 2024

    In FreeBSD 12.0-STABLE before r350261, 12.0-RELEASE before 12.0-RELEASE-p8, 11.3-STABLE before r350263, 11.3-RELEASE before 11.3-RELEASE-p1, and 11.2-RELEASE before 11.2-RELEASE-p12, system calls operating on file descriptors as part of mqueuefs did not properly release the reference allowing a malicious user to overflow the counter allowing access to files, directories, and sockets opened by processes owned by other users.

    Published:26 Jul 2019
    8.8
    High

    CVE-2019-5602

    Last Modified: 21 Nov 2024

    In FreeBSD 12.0-STABLE before r349628, 12.0-RELEASE before 12.0-RELEASE-p7, 11.3-PRERELEASE before r349629, 11.3-RC3 before 11.3-RC3-p1, and 11.2-RELEASE before 11.2-RELEASE-p11, a bug in the cdrom driver allows users with read access to the cdrom device to arbitrarily overwrite kernel memory when media is present thereby allowing a malicious user in the operator group to gain root privileges.

    Published:3 Jul 2019
    8.8
    High

    CVE-2019-5596

    Last Modified: 18 Jun 2020

    In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEASE-p3, a bug in the reference count implementation for UNIX domain sockets can cause a file structure to be incorrectly released potentially allowing a malicious local user to gain root privileges or escape from a jail.

    Source:gr4yf0x
    Published:12 Feb 2019
    6.5
    Medium

    CVE-2019-5591

    Last Modified: 24 Oct 2025

    A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

    Published:14 Aug 2020
    9.8
    Critical

    CVE-2019-5544

    Last Modified: 30 Oct 2025

    OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

    Published:6 Dec 2019
    7.8
    High

    CVE-2019-5526

    Last Modified: 16 May 2019

    VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a windows host where Workstation is installed.

    Source:Miguel Mendez Z. & Claudio Cortes C.
    Published:15 May 2019
    5.3
    Medium

    CVE-2019-5513

    Last Modified: 21 Nov 2024

    VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address.

    Published:9 Apr 2019
    8.8
    High

    CVE-2019-5512

    Last Modified: 25 Mar 2019

    VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately. Successful exploitation of this issue may allow hijacking of COM classes used by the VMX process, on a Windows host, leading to elevation of privilege.

    Source:Google Security Research
    Published:9 Apr 2019
    5.5
    Medium

    CVE-2019-5489

    Last Modified: 21 Nov 2024

    The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page cache access patterns of other processes on the same system, potentially allowing sniffing of secret information. (Fixing this affects the output of the fincore program.) Limited remote exploitation may be possible, as demonstrated by latency differences in accessing public files from an Apache HTTP Server.

    Published:6 Jan 2019
    10
    Critical

    CVE-2019-5485

    Last Modified: 25 Sept 2019

    NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be injected through the repository name.

    Source:Semen Alexandrovich Lyhin
    Published:13 Sept 2019
    8.8
    High

    CVE-2019-5475

    Last Modified: 21 Nov 2024

    The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied vulnerable data, such as the Yum Configuration Capability.

    Published:3 Sept 2019
    9.8
    Critical

    CVE-2019-5454

    Last Modified: 21 Nov 2024

    SQL Injection in the Nextcloud Android app prior to version 3.0.0 allows to destroy a local cache when a harmful query is executed requiring to resetup the account.

    Published:30 Jul 2019
    9.8
    Critical

    CVE-2019-5434

    Last Modified: 3 Dec 2019

    An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.

    Source:crlf
    Published:6 May 2019
    7.5
    High

    CVE-2019-5427

    Last Modified: 5 Sept 2025

    c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

    Published:17 Apr 2019
    9.8
    Critical

    CVE-2019-5420

    Last Modified: 2 May 2019

    A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.

    Source:Metasploit
    Published:13 Mar 2019
    7.5
    High

    CVE-2019-5418

    Last Modified: 21 Mar 2019

    There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.

    Source:NotoriousRebel
    Published:13 Mar 2019
    8.1
    High

    CVE-2019-5414

    Last Modified: 21 Nov 2024

    If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.

    Published:17 Mar 2019
    9.8
    Critical

    CVE-2019-5413

    Last Modified: 21 Nov 2024

    An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

    Published:28 Oct 2018
    5.3
    Medium

    CVE-2019-5392

    Last Modified: 23 Sept 2019

    A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

    Source:Lazy Hacker
    Published:5 Jun 2019