2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13493 | — | — | 1.6% | Jul 17, 2019 | In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u... |
| CVE-2019-13448 | — | — | 0.8% | Jul 17, 2019 | An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ... |
| CVE-2019-13447 | — | — | 1.7% | Jul 17, 2019 | An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ... |
| CVE-2019-12876 | — | — | 4.6% | Jul 17, 2019 | Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, l... |
| CVE-2019-11535 | — | — | 5.1% | Jul 17, 2019 | Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) al... |
| CVE-2019-13631 | — | — | 0.8% | Jul 17, 2019 | In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device ... |
| CVE-2019-13584 | — | — | 3.4% | Jul 17, 2019 | The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP ... |
| CVE-2019-13614 | — | — | 3.4% | Jul 17, 2019 | CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and e... |
| CVE-2019-13613 | — | — | 3.4% | Jul 17, 2019 | CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180... |
| CVE-2019-13403 | — | — | 1.9% | Jul 17, 2019 | Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leadi... |
| CVE-2019-13346 | — | — | 2.2% | Jul 17, 2019 | In MyT 1.5.1, the User[username] parameter has XSS. |
| CVE-2019-12475 | — | — | 1.0% | Jul 17, 2019 | In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation. |
| CVE-2019-12175 | — | — | 1.4% | Jul 17, 2019 | In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka K... |
| CVE-2019-10353 | — | — | 1.5% | Jul 17, 2019 | CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obt... |
| CVE-2019-10352 | — | — | 10.2% | Jul 17, 2019 | A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/... |
| CVE-2019-13453 | — | — | 2.0% | Jul 17, 2019 | Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a ... |
| CVE-2019-1010084 | — | — | 1.1% | Jul 17, 2019 | Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unath... |
| CVE-2019-1010083 | — | — | 1.9% | Jul 17, 2019 | The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The atta... |
| CVE-2019-13446 | — | — | — | Jul 17, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13625 | — | — | 2.4% | Jul 17, 2019 | NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a pro... |
| CVE-2019-13624 | — | — | 1.9% | Jul 17, 2019 | In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote character... |
| CVE-2019-13623 | — | — | 5.0% | Jul 17, 2019 | In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)... |
| CVE-2019-3571 | — | — | 0.8% | Jul 16, 2019 | An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send fi... |
| CVE-2019-9700 | — | — | 0.3% | Jul 16, 2019 | Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may al... |
| CVE-2019-13359 | — | — | 26.5% | Jul 16, 2019 | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now