2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-11689HIGH8.1An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-11688HIGH7.4An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf...
CVE-2019-10682HIGH7.5django-nopassword before 5.0.0 stores cleartext secrets in the database.
CVE-2019-10146MEDIUM4.7A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to t...
CVE-2019-14884MEDIUM6.1A vulnerability was found in Moodle 3.7 before 3.73, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possib...
CVE-2019-14883MEDIUM5.3A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments ...
CVE-2019-14882MEDIUM6.1A vulnerability was found in Moodle 3.7 to 3.7.3, 3.6 to 3.6.7, 3.5 to 3.5.9 and earlier where an open redirect existed ...
CVE-2019-14881MEDIUM6.1A vulnerability was found in moodle 3.7 before 3.7.3, where there is blind XSS reflected in some locations where user em...
CVE-2019-20510——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-13456. Reason: This candidate is a duplicate of ...
CVE-2019-11939HIGH7.5Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the pay...
CVE-2019-20498CRITICAL9.8cPanel before 82.0.18 allows WebDAV authentication bypass because the connection-sharing logic is incorrect (SEC-534).
CVE-2019-20497MEDIUM5.4cPanel before 82.0.18 allows stored XSS via WHM Backup Restoration (SEC-533).
CVE-2019-20496MEDIUM5.5cPanel before 82.0.18 allows attackers to conduct arbitrary chown operations as root during log processing (SEC-532).
CVE-2019-20495MEDIUM6.5cPanel before 82.0.18 allows attackers to read an arbitrary database via MySQL dump streaming (SEC-531).
CVE-2019-20494LOW3.3In cPanel before 82.0.18, Cpanel::Rand::Get can produce a predictable series of numbers (SEC-525).
CVE-2019-20493MEDIUM6.1cPanel before 82.0.18 allows self-XSS because JSON string escaping is mishandled (SEC-520).
CVE-2019-20492HIGH8.8cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
CVE-2019-20490HIGH8.8cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
CVE-2019-11074HIGH7.2A Write to Arbitrary Location in Disk vulnerability exists in PRTG Network Monitor 19.1.49 and below that allows attacke...
CVE-2019-20453HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20452HIGH8.8A problem was found in Pydio Core before 8.2.4 and Pydio Enterprise before 8.2.4. A PHP object injection is present in t...
CVE-2019-20407MEDIUM4.3The ConfigureBambooRelease resource in Jira Software and Jira Software Data Center before version 8.6.1 allows authentic...
CVE-2019-20105MEDIUM4.9The EditApplinkServlet resource in the Atlassian Application Links plugin before version 5.4.20, from version 6.0.0 befo...
CVE-2019-20326HIGH7.8A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg....
CVE-2019-20191HIGH7.5Oxygen XML Editor 21.1.1 allows XXE to read any file.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now