2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16974 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-16969 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the U... |
| CVE-2019-16970 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the ... |
| CVE-2019-16968 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an... |
| CVE-2019-16967 | MEDIUM | 6.1 | 1.3% | Oct 21, 2019 | An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager ... |
| CVE-2019-16966 | MEDIUM | 6.1 | 1.1% | Oct 21, 2019 | An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for Fr... |
| CVE-2019-18203 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ad... |
| CVE-2019-16991 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, whi... |
| CVE-2019-16989 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable c... |
| CVE-2019-16988 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" ... |
| CVE-2019-16987 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming f... |
| CVE-2019-16986 | MEDIUM | 6.5 | 1.4% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which t... |
| CVE-2019-16985 | MEDIUM | 6.5 | 1.1% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the UR... |
| CVE-2019-16984 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming fro... |
| CVE-2019-16983 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface... |
| CVE-2019-16982 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable comin... |
| CVE-2019-16981 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" varia... |
| CVE-2019-16990 | MEDIUM | 6.5 | 1.3% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from ... |
| CVE-2019-16979 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-16978 | MEDIUM | 6.1 | 0.9% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the UR... |
| CVE-2019-17409 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter. |
| CVE-2019-16862 | MEDIUM | 6.1 | 1.5% | Oct 21, 2019 | Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbi... |
| CVE-2019-10715 | MEDIUM | 5.4 | 0.5% | Oct 21, 2019 | There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Seque... |
| CVE-2019-18216 | MEDIUM | 6.8 | 0.4% | Oct 20, 2019 | The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of... |
| CVE-2019-18209 | MEDIUM | 6.1 | 0.7% | Oct 19, 2019 | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now