2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-5117HIGH8.8Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web r...
CVE-2019-5116HIGH8.8An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web req...
CVE-2019-13549HIGH7.5Rittal Chiller SK 3232-Series web interface as built upon Carel pCOWeb firmware A1.5.3 – B1.2.4. The authentication mech...
CVE-2019-4399HIGH7.5IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 uses weaker than expected cryptographic algorithms th...
CVE-2019-4036HIGH7.5IBM Security Access Manager Appliance could allow unauthenticated attacker to cause a denial of service in the reverse p...
CVE-2019-8087HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful e...
CVE-2019-8086HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful e...
CVE-2019-8082HIGH7.5Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploi...
CVE-2019-8081HIGH7.5Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have an authentication bypass vulnerability. Successful exploita...
CVE-2019-17596HIGH7.5Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA...
CVE-2019-18417HIGH8.8Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can resu...
CVE-2019-18414HIGH8.8Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulner...
CVE-2019-12095HIGH8.8Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated ...
CVE-2019-5013HIGH7.8An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in...
CVE-2019-5012HIGH7.8An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in...
CVE-2019-11021HIGH7.2admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execu...
CVE-2019-18201HIGH7.5An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o...
CVE-2019-6692HIGH7.8A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker t...
CVE-2019-18409HIGH7.8The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files...
CVE-2019-18408HIGH7.5archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free i...
CVE-2019-15703HIGH7.5An Insufficient Entropy in PRNG vulnerability in Fortinet FortiOS 6.2.1, 6.2.0, 6.0.8 and below for device not enable ha...
CVE-2019-18213HIGH8.8XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 fo...
CVE-2019-8238HIGH7.5Adobe Acrobat and Reader versions 2019.010.20100 and earlier; 2019.010.20099 and earlier versions; 2017.011.30140 and ea...
CVE-2019-18385HIGH7.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. An unauthenticated attacker can download log files via the...
CVE-2019-18383HIGH7.5An issue was discovered on TerraMaster FS-210 4.0.19 devices. One can download backup files remotely from terramaster_TN...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now