2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2019-17318HIGH8.8SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
CVE-2019-17317HIGH7.2SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
CVE-2019-17316HIGH8.8SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
CVE-2019-17315HIGH7.2SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
CVE-2019-3688HIGH7.1The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8....
CVE-2019-16263HIGH7.4The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although...
CVE-2019-15747HIGH8.8SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Syste...
CVE-2019-17219HIGH8.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the devic...
CVE-2019-17217HIGH8.8An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF prot...
CVE-2019-17214HIGH7.5The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI.
CVE-2019-17199HIGH7.5www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of ...
CVE-2019-17191HIGH7.5The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, witho...
CVE-2019-17188HIGH7.2An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An...
CVE-2019-16865HIGH7.5An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can eith...
CVE-2019-17183HIGH7.5Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists.
CVE-2019-17180HIGH7.8Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrate...
CVE-2019-11655HIGH8.8Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could...
CVE-2019-6015HIGH7.5FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue w...
CVE-2019-6776HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0...
CVE-2019-6775HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-6774HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.168...
CVE-2019-13320HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13319HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207...
CVE-2019-13317HIGH7.8This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0....
CVE-2019-13316HIGH7.8This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0....

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now