2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9657 | — | — | 0.3% | Jul 11, 2019 | Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs be... |
| CVE-2019-3854 | — | — | — | Jul 11, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-13029 | — | — | 2.5% | Jul 11, 2019 | Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 ... |
| CVE-2019-10651 | — | — | 4.3% | Jul 11, 2019 | An issue was discovered in the Core Server in Ivanti Endpoint Manager (EPM) 2017.3 before SU7 and 2018.x before 2018.3 S... |
| CVE-2019-13562 | — | — | 1.8% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow XSS, as demonstrated by the /www/ping_response.cgi ping_ipaddr para... |
| CVE-2019-13561 | — | — | 8.4% | Jul 11, 2019 | D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharac... |
| CVE-2019-13507 | — | — | 2.0% | Jul 11, 2019 | hidea.com AZ Admin 1.0 has news_det.php?cod= SQL Injection. |
| CVE-2019-13506 | — | — | 1.3% | Jul 11, 2019 | @nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS. |
| CVE-2019-12540 | — | — | 2.3% | Jul 11, 2019 | An issue was discovered in Zoho ManageEngine ServiceDesk Plus 10.5. There is XSS via the WorkOrder.do search field. |
| CVE-2019-12363 | — | — | 0.6% | Jul 11, 2019 | An CSRF issue was discovered in the JN-Jones MyBB-2FA plugin through 2014-11-05 for MyBB. An attacker can forge a reques... |
| CVE-2019-1010003 | — | — | 0.6% | Jul 11, 2019 | Leanote prior to version 2.6 is affected by: Cross Site Scripting (XSS). |
| CVE-2019-13489 | — | — | 1.4% | Jul 10, 2019 | Trape through 2019-05-08 has SQL injection via the data[2] variable in core/db.py, as demonstrated by the /bs t paramete... |
| CVE-2019-13488 | — | — | 1.1% | Jul 10, 2019 | A cross-site scripting (XSS) vulnerability in static/js/trape.js in Trape through 2019-05-08 allows remote attackers to ... |
| CVE-2019-13381 | — | — | — | Jul 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-0329 | — | — | 1.3% | Jul 10, 2019 | SAP Information Steward, version 4.2, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scrip... |
| CVE-2019-0328 | — | — | 3.4% | Jul 10, 2019 | ABAP Tests Modules (SAP Basis, versions 7.0, 7.1, 7.3, 7.31, 7.4, 7.5) of SAP NetWeaver Process Integration enables an a... |
| CVE-2019-0327 | — | — | 2.1% | Jul 10, 2019 | SAP NetWeaver for Java Application Server - Web Container, (engineapi, versions 7.1, 7.2, 7.3, 7.31, 7.4 and 7.5), (serv... |
| CVE-2019-0326 | — | — | 1.3% | Jul 10, 2019 | SAP BusinessObjects Business Intelligence Platform (BI Workspace) (Enterprise), versions 4.1, 4.2, 4.3, does not suffici... |
| CVE-2019-0325 | — | — | 0.8% | Jul 10, 2019 | SAP ERP HCM (SAP_HRCES) , version 3, does not perform necessary authorization checks for a report that reads payroll dat... |
| CVE-2019-0322 | — | — | 2.6% | Jul 10, 2019 | SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), al... |
| CVE-2019-0321 | — | — | 1.3% | Jul 10, 2019 | ABAP Server and ABAP Platform (SAP Basis), versions, 7.31, 7.4, 7.5, do not sufficiently encode user-controlled inputs, ... |
| CVE-2019-0319 | — | — | 2.5% | Jul 10, 2019 | The SAP Gateway, versions 7.5, 7.51, 7.52 and 7.53, allows an attacker to inject content which is displayed in the form ... |
| CVE-2019-0318 | — | — | 1.4% | Jul 10, 2019 | Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49,... |
| CVE-2019-0281 | — | — | 1.3% | Jul 10, 2019 | SAPUI5 and OpenUI5, before versions 1.38.39, 1.44.39, 1.52.25, 1.60.6 and 1.63.0, does not sufficiently encode user-cont... |
| CVE-2019-5221 | — | — | 0.5% | Jul 10, 2019 | There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now