Vulnerabilities (CVE)

Filtered by CWE-19
Total 225 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-28552 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 6.5 MEDIUM
Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2026-28539 1 Huawei 1 Harmonyos 2026-06-17 N/A 6.2 MEDIUM
Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2025-20311 2026-06-17 N/A 7.4 HIGH
A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an egress port to become blocked and drop all outbound traffic. This vulnerability is due to improper handling of crafted Ethernet frames. An attacker could exploit this vulnerability by sending crafted Ethernet frames through an affected switch. A successful exploit could allow the attacker to cause the egress port to which the crafted frame is forwarded to start dropping all frames, resulting in a denial of service (DoS) condition.
CVE-2019-9870 1 Oembed Project 1 Oembed 2026-06-17 7.5 HIGH 9.8 CRITICAL
plugin.js in the w8tcha oEmbed plugin before 2019-03-14 for CKEditor mishandles SCRIPT elements.
CVE-2019-9673 1 Freenetproject 1 Freenet 2026-06-17 6.8 MEDIUM 8.8 HIGH
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
CVE-2019-9573 1 Mishubd 1 Wp Human Resource Management 2026-06-17 5.0 MEDIUM 7.5 HIGH
The WP Human Resource Management plugin before 2.2.6 for WordPress mishandles leave applications.
CVE-2019-9563 1 Bluemind 1 Bluemind 2026-06-17 5.0 MEDIUM 7.5 HIGH
In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
CVE-2019-6440 1 Zemana 1 Antimalware 2026-06-17 7.5 HIGH 9.8 CRITICAL
Zemana AntiMalware before 3.0.658 Beta mishandles update logic.
CVE-2019-4236 2 Hp, Ibm 2 Hp-ux, Spectrum Protect 2026-06-17 3.6 LOW 4.4 MEDIUM
A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if there are more than twelve ACL entries associated with the object in total. As a result, it could allow a local attacker to restore or retrieve the object with incorrect ACL entries. IBM X-Force ID: 159418.
CVE-2019-3554 1 Facebook 1 Wangle 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
Wangle's AcceptRoutingHandler incorrectly casts a socket when accepting a TLS 1.3 connection, leading to a potential denial of service attack against systems accepting such connections. This affects versions of Wangle prior to v2019.01.14.00
CVE-2019-1083 1 Microsoft 9 .net Framework, Windows 10, Windows 7 and 6 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when Microsoft Common Object Runtime Library improperly handles web requests, aka '.NET Denial of Service Vulnerability'.
CVE-2019-14794 1 Metabox 1 Meta Box 2026-06-17 5.0 MEDIUM 7.5 HIGH
The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.
CVE-2019-13917 2 Debian, Exim 2 Debian Linux, Exim 2026-06-17 10.0 HIGH 9.8 CRITICAL
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).
CVE-2019-13624 1 Onosproject 1 Onos 2026-06-17 10.0 HIGH 9.8 CRITICAL
In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.
CVE-2019-12828 1 Ea 1 Origin 2026-06-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath argument supplied with a Windows network share.
CVE-2019-11070 2 Webkitgtk, Wpewebkit 2 Webkitgtk, Wpe Webkit 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an error resulting in deanonymization. This issue was corrected by changing the way livestreams are downloaded.
CVE-2019-10477 2 Fusioninventory, Glpi-project 2 Fusioninventory, Glpi 2026-06-17 5.0 MEDIUM 7.5 HIGH
The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions.
CVE-2019-0982 1 Microsoft 1 Asp.net Core 2026-06-17 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
CVE-2019-0981 1 Microsoft 10 .net Core, .net Framework, Windows 10 and 7 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0980.
CVE-2019-0980 1 Microsoft 10 .net Core, .net Framework, Windows 10 and 7 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0820, CVE-2019-0981.