2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17318 | HIGH | 8.8 | 1.2% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user. |
| CVE-2019-17317 | HIGH | 7.2 | 1.4% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user. |
| CVE-2019-17316 | HIGH | 8.8 | 1.5% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user. |
| CVE-2019-17315 | HIGH | 7.2 | 1.4% | Oct 7, 2019 | SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user. |
| CVE-2019-3688 | HIGH | 7.1 | 0.3% | Oct 7, 2019 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.... |
| CVE-2019-16263 | HIGH | 7.4 | 1.0% | Oct 7, 2019 | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although... |
| CVE-2019-15747 | HIGH | 8.8 | 1.1% | Oct 7, 2019 | SITOS six Build v6.2.1 allows a user with the user role of Seminar Coordinator to escalate their permission to the Syste... |
| CVE-2019-17219 | HIGH | 8.8 | 0.6% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. By default, the devic... |
| CVE-2019-17217 | HIGH | 8.8 | 0.5% | Oct 6, 2019 | An issue was discovered on V-Zug Combi-Steam MSLQ devices before Ethernet R07 and before WLAN R05. There is no CSRF prot... |
| CVE-2019-17214 | HIGH | 7.5 | 1.9% | Oct 6, 2019 | The WebARX plugin 1.3.0 for WordPress allows firewall bypass by appending &cc=1 to a URI. |
| CVE-2019-17199 | HIGH | 7.5 | 10.0% | Oct 5, 2019 | www/getfile.php in WPO WebPageTest 19.04 on Windows allows Directory Traversal (for reading arbitrary files) because of ... |
| CVE-2019-17191 | HIGH | 7.5 | 1.8% | Oct 5, 2019 | The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, witho... |
| CVE-2019-17188 | HIGH | 7.2 | 1.4% | Oct 4, 2019 | An unrestricted file upload vulnerability was discovered in catalog/productinfo/imageupload in Fecshop FecMall 2.3.4. An... |
| CVE-2019-16865 | HIGH | 7.5 | 3.2% | Oct 4, 2019 | An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can eith... |
| CVE-2019-17183 | HIGH | 7.5 | 1.4% | Oct 4, 2019 | Foxit Reader before 9.7 allows an Access Violation and crash if insufficient memory exists. |
| CVE-2019-17180 | HIGH | 7.8 | 0.7% | Oct 4, 2019 | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrate... |
| CVE-2019-11655 | HIGH | 8.8 | 1.5% | Oct 4, 2019 | Unrestricted file upload vulnerability in Micro Focus ArcSight Logger, version 6.7.0 and later. This vulnerability could... |
| CVE-2019-6015 | HIGH | 7.5 | 1.6% | Oct 4, 2019 | FON2601E-SE, FON2601E-RE, FON2601E-FSW-S, and FON2601E-FSW-B with firmware versions 1.1.7 and earlier contain an issue w... |
| CVE-2019-6776 | HIGH | 7.8 | 3.9% | Oct 4, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0... |
| CVE-2019-6775 | HIGH | 7.8 | 4.2% | Oct 4, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207... |
| CVE-2019-6774 | HIGH | 7.8 | 4.2% | Oct 4, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.4.1.168... |
| CVE-2019-13320 | HIGH | 7.8 | 4.1% | Oct 4, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207... |
| CVE-2019-13319 | HIGH | 7.8 | 4.1% | Oct 4, 2019 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 9.5.0.207... |
| CVE-2019-13317 | HIGH | 7.8 | 7.7% | Oct 4, 2019 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.... |
| CVE-2019-13316 | HIGH | 7.8 | 7.7% | Oct 4, 2019 | This vulnerability allows remote atackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.5.0.... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now