2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16072CRITICAL9.8An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows...
CVE-2019-16071HIGH8.8Enigma NMS 65.0.0 and prior allows administrative users to create low-privileged accounts that do not have the ability t...
CVE-2019-16529MEDIUM5.3An issue was discovered in the CheckUser extension through 1.35.0 for MediaWiki. Oversighted edit summaries are still vi...
CVE-2019-16069MEDIUM6.1A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that...
CVE-2019-16068HIGH8.8A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri...
CVE-2019-16063HIGH7.5NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data rendered within web pages. It is possible for an atta...
CVE-2019-15539MEDIUM6.1The proj_doc_edit_page.php Project Documentation feature in MantisBT before 2.21.3 has a stored cross-site scripting (XS...
CVE-2019-15124MEDIUM6.1In the MobileFrontend extension for MediaWiki, XSS exists within the edit summary field of the watchlist feed. This affe...
CVE-2019-20526MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter.
CVE-2019-20525MEDIUM6.1Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter.
CVE-2019-20521MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
CVE-2019-20520MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI.
CVE-2019-20519MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address.
CVE-2019-20518MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI.
CVE-2019-20517MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI.
CVE-2019-20516MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI.
CVE-2019-20515MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI.
CVE-2019-20514MEDIUM6.1ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI.
CVE-2019-20513MEDIUM6.1Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
CVE-2019-16375MEDIUM5.4An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.11, and Community Edition 5.0.x through 5...
CVE-2019-16338HIGH7.8The tfo_common component in HwordApp.dll in Hancom Office 9.6.1.7634 allows a use-after-free via a crafted .docx file.
CVE-2019-16337HIGH7.8The hncbd90 component in Hancom Office 9.6.1.9403 allows a use-after-free via an unknown object in a crafted .docx file.
CVE-2019-16070MEDIUM6.1A number of stored Cross-site Scripting (XSS) vulnerabilities were identified in NETSAS Enigma NMS 65.0.0 and prior that...
CVE-2019-16067HIGH7.5NETSAS Enigma NMS 65.0.0 and prior utilises basic authentication over HTTP for enforcing access control to the web appli...
CVE-2019-16066HIGH8.8An unrestricted file upload vulnerability exists in user and system file upload functions in NETSAS Enigma NMS 65.0.0 an...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now