2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-5220There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently ...
CVE-2019-13279TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when proces...
CVE-2019-13278TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user ...
CVE-2019-13276TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. ...
CVE-2019-13122A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 throu...
CVE-2019-12470Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed...
CVE-2019-12469MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed...
CVE-2019-12474Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recen...
CVE-2019-12473Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by queryi...
CVE-2019-12472An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypa...
CVE-2019-12471Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to ...
CVE-2019-12466Wikimedia MediaWiki through 1.32.1 allows CSRF.
CVE-2019-12468An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Sp...
CVE-2019-12467MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out ...
CVE-2019-13396FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in...
CVE-2019-13240An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that...
CVE-2019-10653An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page.
CVE-2019-12723An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and...
CVE-2019-10122eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTT...
CVE-2019-10121eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack au...
CVE-2019-10120On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAuto...
CVE-2019-10119eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack au...
CVE-2019-13475In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to ex...
CVE-2019-13472PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file.
CVE-2019-9150Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now