2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-13389MEDIUM6.1RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection heade...
CVE-2019-12498CRITICAL9.8The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api...
CVE-2019-19324HIGH7.5Xmidt cjwt through 1.0.1 before 2019-11-25 maps unsupported algorithms to alg=none, which sometimes leads to untrusted a...
CVE-2019-19148CRITICAL9.8Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH. Tell...
CVE-2019-16258MEDIUM6.8The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by ma...
CVE-2019-15665HIGH7.2An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida...
CVE-2019-15664LOW2.7An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to valida...
CVE-2019-15663LOW2.7An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120404 in KfeCo10X64.sys fails to valida...
CVE-2019-15662LOW2.7An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120444 in KfeCo10X64.sys fails to valida...
CVE-2019-15075HIGH7.5An issue was discovered in iNextrix ASTPP before 4.0.1. web_interface/astpp/application/config/config.php does not have ...
CVE-2019-15661HIGH7.2An issue was discovered in Rivet Killer Control Center before 2.1.1352. IOCTL 0x120004 in KfeCo10X64.sys fails to valida...
CVE-2019-14855HIGH7.5A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An att...
CVE-2019-19345HIGH7.8A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification v...
CVE-2019-10221MEDIUM6.1A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from t...
CVE-2019-10179MEDIUM6.1A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not ...
CVE-2019-19487HIGH8.8Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection ...
CVE-2019-19486MEDIUM6.5Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a pl...
CVE-2019-19484MEDIUM6.1Open redirect via parameter ‘p’ in login.php in Centreon (19.04.4 and below) allows an attacker to craft a payload and e...
CVE-2019-19029HIGH7.2Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via user-groups in the VMware Har...
CVE-2019-19026MEDIUM4.9Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows SQL Injection via project quotas in the VMware ...
CVE-2019-19025HIGH8.8Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 allows CSRF in the VMware Harbor Container Registry fo...
CVE-2019-19023HIGH8.8Cloud Native Computing Foundation Harbor prior to 1.8.6 and 1.9.3 has a Privilege Escalation Vulnerability in the VMware...
CVE-2019-18785HIGH7.5SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
CVE-2019-18782MEDIUM5.3SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechan...
CVE-2019-16108HIGH7.5phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now