Skip to main content

CWE archive

CWE-19 CVEs

Programmatic archive

235 CVEs tagged with CWE-1934 Critical, 105 High, 92 Medium, 4 Low, 0 Unrated.

CVE-2026-28552

Published Mar 5, 2026

Out-of-bounds write vulnerability in the IMS module. Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-28539

Published Mar 5, 2026

Data processing vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.2 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-20311

Published Sep 24, 2025

A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an unauthenticated, adjacent attacker to cause an…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9

CVE-2023-39395

Published Aug 13, 2023

Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1651

Published Jul 17, 2020

On Juniper Networks MX series, receipt of a stream of specific Layer 2 frames may cause a memory leak resulting in the packet forwarding engine (PFE) on the line card to crash and…

CVSS 6.5 · Medium

CVE-2020-3232

Published Jun 3, 2020

A vulnerability in the Simple Network Management Protocol (SNMP) implementation in Cisco ASR 920 Series Aggregation Services Router model ASR920-12SZ-IM could allow an authenticat…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14794

Published Aug 9, 2019

The Meta Box plugin before 4.16.2 for WordPress mishandles the uploading of files to custom folders.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13917

Published Jul 25, 2019

Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-4236

Published Jul 22, 2019

A IBM Spectrum Protect 7.l client backup or archive operation running for an HP-UX VxFS object is silently skipping Access Control List (ACL) entries from backup or archive if the…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13624

Published Jul 17, 2019

In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote characters within strings that can be used in a shell command.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12828

Published Jun 14, 2019

An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arg…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0941

Published Jun 12, 2019

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerabili…

CVSS 4.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2019-9673

Published Jun 5, 2019

Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0089

Published May 17, 2019

Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.04.181.0, and SPS_SoC-X_04.00.0…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0982

Published May 16, 2019

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0981

Published May 16, 2019

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This…

CVSS 7.5 · High

CVE-2019-0980

Published May 16, 2019

A denial of service vulnerability exists when .NET Framework or .NET Core improperly handle web requests, aka '.Net Framework and .Net Core Denial of Service Vulnerability'. This…

CVSS 7.5 · High

CVE-2019-0947

Published May 16, 2019

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity E…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-0945

Published May 16, 2019

A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity E…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11070

Published Apr 10, 2019

WebKitGTK and WPE WebKit prior to version 2.24.1 failed to properly apply configured HTTP proxy settings when downloading livestream video (HLS, DASH, or Smooth Streaming), an err…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 235 CVEsPage 1 of 10