2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-13493In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u...
CVE-2019-13448An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ...
CVE-2019-13447An issue was discovered in Sertek Xpare 3.67. The login form does not sanitize input data. Because of this, a malicious ...
CVE-2019-12876Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, l...
CVE-2019-11535Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) al...
CVE-2019-13631In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device ...
CVE-2019-13584The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP ...
CVE-2019-13614CMD_SET_CONFIG_COUNTRY in the TP-Link Device Debug protocol in TP-Link Archer C1200 1.0.0 Build 20180502 rel.45702 and e...
CVE-2019-13613CMD_FTEST_CONFIG in the TP-Link Device Debug protocol in TP-Link Wireless Router Archer Router version 1.0.0 Build 20180...
CVE-2019-13403Temenos CWX version 8.9 has an Broken Access Control vulnerability in the module /CWX/Employee/EmployeeEdit2.aspx, leadi...
CVE-2019-13346In MyT 1.5.1, the User[username] parameter has XSS.
CVE-2019-12475In MicroStrategy Web before 10.4.6, there is stored XSS in metric due to insufficient input validation.
CVE-2019-12175In Zeek Network Security Monitor (formerly known as Bro) before 2.6.2, a NULL pointer dereference in the Kerberos (aka K...
CVE-2019-10353CSRF tokens in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier did not expire, thereby allowing attackers able to obt...
CVE-2019-10352A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/...
CVE-2019-13453Zipios before 0.1.7 does not properly handle certain malformed zip archives and can go into an infinite loop, causing a ...
CVE-2019-1010084Dancer::Plugin::SimpleCRUD 1.14 and earlier is affected by: Incorrect Access Control. The impact is: Potential for unath...
CVE-2019-1010083The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The atta...
CVE-2019-13446Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13625NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a pro...
CVE-2019-13624In ONOS 1.15.0, apps/yang/web/src/main/java/org/onosproject/yang/web/YangWebResource.java mishandles backquote character...
CVE-2019-13623In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)...
CVE-2019-3571An input validation issue affected WhatsApp Desktop versions prior to 0.3.3793 which allows malicious clients to send fi...
CVE-2019-9700Norton Password Manager, prior to 6.3.0.2082, may be susceptible to an address spoofing issue. This type of issue may al...
CVE-2019-13359In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now