2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16974MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL,...
CVE-2019-16969MEDIUM6.1In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the U...
CVE-2019-16970MEDIUM6.1In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the ...
CVE-2019-16968MEDIUM6.1An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an...
CVE-2019-16967MEDIUM6.1An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager ...
CVE-2019-16966MEDIUM6.1An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for Fr...
CVE-2019-18203MEDIUM6.1On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ad...
CVE-2019-16991MEDIUM6.1In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, whi...
CVE-2019-16989MEDIUM6.1In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable c...
CVE-2019-16988MEDIUM6.1In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" ...
CVE-2019-16987MEDIUM6.1In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming f...
CVE-2019-16986MEDIUM6.5In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which t...
CVE-2019-16985MEDIUM6.5In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the UR...
CVE-2019-16984MEDIUM6.1In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming fro...
CVE-2019-16983MEDIUM6.1In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface...
CVE-2019-16982MEDIUM6.1In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable comin...
CVE-2019-16981MEDIUM6.1In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" varia...
CVE-2019-16990MEDIUM6.5In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from ...
CVE-2019-16979MEDIUM6.1In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL,...
CVE-2019-16978MEDIUM6.1In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the UR...
CVE-2019-17409MEDIUM6.1Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
CVE-2019-16862MEDIUM6.1Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbi...
CVE-2019-10715MEDIUM5.4There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Seque...
CVE-2019-18216MEDIUM6.8The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of...
CVE-2019-18209MEDIUM6.1templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now