2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5680 | — | — | 0.4% | Jul 19, 2019 | In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in whic... |
| CVE-2019-12821 | — | — | 0.9% | Jul 19, 2019 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner, while adding a device to the a... |
| CVE-2019-12820 | — | — | 0.5% | Jul 19, 2019 | A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app s... |
| CVE-2019-12945 | — | — | — | Jul 19, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-12453 | — | — | 1.0% | Jul 19, 2019 | In MicroStrategy Web before 10.1 patch 10, stored XSS is possible in the FLTB parameter due to missing input validation. |
| CVE-2019-11553 | — | — | 1.0% | Jul 19, 2019 | In Code42 for Enterprise through 6.8.4, an administrator without web restore permission but with the ability to manage u... |
| CVE-2019-12193 | — | — | 1.5% | Jul 19, 2019 | H3C H3Cloud OS all versions allows SQL injection via the ear/grid_event sidx parameter. |
| CVE-2019-1010136 | — | — | 1.7% | Jul 19, 2019 | ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impa... |
| CVE-2019-1010113 | — | — | 0.8% | Jul 19, 2019 | Premium Software CLEditor 1.4.5 and earlier is affected by: Cross Site Scripting (XSS). The impact is: An attacker might... |
| CVE-2019-1010101 | — | — | 3.4% | Jul 19, 2019 | Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with... |
| CVE-2019-1010100 | — | — | 1.3% | Jul 19, 2019 | Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code executio... |
| CVE-2019-1167 | — | — | 1.1% | Jul 19, 2019 | A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attac... |
| CVE-2019-13984 | — | — | 1.6% | Jul 19, 2019 | Directus 7 API before 2.3.0 does not validate uploaded files. Regardless of the file extension or MIME type, there is a ... |
| CVE-2019-13983 | — | — | 1.5% | Jul 19, 2019 | Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Serv... |
| CVE-2019-13982 | — | — | 1.1% | Jul 19, 2019 | interfaces/markdown/input.vue in Directus 7 Application before 7.7.0 does not sanitize Markdown text before rendering a ... |
| CVE-2019-13981 | — | — | 1.5% | Jul 19, 2019 | In Directus 7 API through 2.3.0, remote attackers can read image files via a direct request for a filename under the upl... |
| CVE-2019-13980 | — | — | 2.5% | Jul 19, 2019 | In Directus 7 API through 2.3.0, uploading of PHP files is blocked only when the Apache HTTP Server is used, leading to ... |
| CVE-2019-13979 | — | — | 2.6% | Jul 19, 2019 | In Directus 7 API before 2.2.1, uploading of PHP files is not blocked, leading to uploads/_/originals remote code execut... |
| CVE-2019-1010247 | — | — | 1.3% | Jul 19, 2019 | ZmartZone IAM mod_auth_openidc 2.3.10.1 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Redirecti... |
| CVE-2019-1010245 | — | — | 3.6% | Jul 19, 2019 | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact... |
| CVE-2019-12946 | — | — | 1.4% | Jul 19, 2019 | Elcom CMS before 10.7 has SQL Injection via EventSearchByState.aspx and EventSearchAdv.aspx. |
| CVE-2019-1010151 | — | — | 2.0% | Jul 19, 2019 | zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/p... |
| CVE-2019-13648 | — | — | 0.6% | Jul 19, 2019 | In the Linux kernel through 5.2.1 on the powerpc platform, when hardware transactional memory is disabled, a local user ... |
| CVE-2019-13978 | — | — | 1.5% | Jul 19, 2019 | Ovidentia 8.4.3 has SQL Injection via the id parameter in an index.php?tg=delegat&idx=mem request. |
| CVE-2019-13977 | — | — | 1.5% | Jul 19, 2019 | index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now