2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14884MEDIUM6.1A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib...
CVE-2019-14883MEDIUM5.3A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments ...
CVE-2019-14882MEDIUM6.1A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed ...
CVE-2019-14881MEDIUM6.1A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em...
CVE-2019-20510Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13456. Reason: This candidate is a duplicate of ...
CVE-2019-11939HIGH7.5Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the pay...
CVE-2019-20498CRITICAL9.8cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
CVE-2019-20497MEDIUM5.4cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2019-20496MEDIUM5.5cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
CVE-2019-20495MEDIUM6.5cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
CVE-2019-20494LOW3.3In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
CVE-2019-20493MEDIUM6.1cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-20492HIGH8.8cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
CVE-2019-20490HIGH8.8cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
CVE-2019-11074HIGH7.2A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attacke...
CVE-2019-20453HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20452HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20407MEDIUM4.3The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authentic...
CVE-2019-20105MEDIUM4.9The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo...
CVE-2019-20326HIGH7.8A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg....
CVE-2019-20191HIGH7.5Oxygen XML Editor 21.1.1 allows XXE to read any file.
CVE-2019-20491MEDIUM5.4cPanel before 82.0.18 allows attackers to leverage virtual mail accounts in order to bypass account suspensions (SEC-508...
CVE-2019-19852MEDIUM4.8An XSS Injection vulnerability exists in Sangoma FreePBX and PBXact 13, 14, and 15 within the Call Event Logging report ...
CVE-2019-19615MEDIUM4.8Multiple XSS vulnerabilities exist in the Backup & Restore module \ v14.0.10.2 through v14.0.10.7 for FreePBX, as shown ...
CVE-2019-19613MEDIUM5.2An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an O...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now