2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19211MEDIUM6.1Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-19210MEDIUM5.4Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed ...
CVE-2019-19209HIGH7.5Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2019-19208CRITICAL9.8Codiad Web IDE through 2.8.4 allows PHP Code injection.
CVE-2019-14887CRITICAL9.1A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly co...
CVE-2019-14512MEDIUM6.1LimeSurvey 3.17.7+190627 has XSS via Boxes in application/extensions/PanelBoxWidget/views/box.php or a label title in ap...
CVE-2019-10091HIGH7.4When TLS is enabled with ssl-endpoint-identification-enabled set to true, Apache Geode fails to perform hostname verific...
CVE-2019-6696MEDIUM6.1An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may al...
CVE-2019-17654HIGH8.8An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow ...
CVE-2019-15708MEDIUM6.7A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and ...
CVE-2019-9474HIGH7.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio...
CVE-2019-9473HIGH7.5In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informatio...
CVE-2019-2216HIGH7.3In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a...
CVE-2019-2089HIGH7.8In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could l...
CVE-2019-2088MEDIUM5.5In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were n...
CVE-2019-2058MEDIUM6.5In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no addition...
CVE-2019-15608MEDIUM5.9The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writ...
CVE-2019-3770MEDIUM6.4Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregisterin...
CVE-2019-3769MEDIUM6.4Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authent...
CVE-2019-18578CRITICAL9Dell EMC XtremIO XMS versions prior to 6.3.0 contain a stored cross-site scripting vulnerability. A low-privileged malic...
CVE-2019-18577MEDIUM6.7Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local...
CVE-2019-18576MEDIUM6.7Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords a...
CVE-2019-19611HIGH7.5An issue was discovered in Halvotec RaQuest 10.23.10801.0. One of the exposed web services allows an anonymous user to a...
CVE-2019-14310CRITICAL9.8Ricoh SP C250DN 1.05 devices allow denial of service (issue 2 of 3). Unauthenticated crafted packets to the IPP service ...
CVE-2019-14309HIGH7.5Ricoh SP C250DN 1.05 devices have a fixed password. FTP service credential were found to be hardcoded within the printer...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now