2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5220 | — | — | 0.2% | Jul 10, 2019 | There is a Factory Reset Protection (FRP) bypass vulnerability on several smartphones. The system does not sufficiently ... |
| CVE-2019-13279 | — | — | 2.7% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple stack-based buffer overflows when proces... |
| CVE-2019-13278 | — | — | 8.8% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains multiple command injections when processing user ... |
| CVE-2019-13276 | — | — | 2.8% | Jul 10, 2019 | TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow in the ssi binary. ... |
| CVE-2019-13122 | — | — | 1.3% | Jul 10, 2019 | A Cross Site Scripting (XSS) vulnerability exists in the template tag used to render message ids in Patchwork v1.1 throu... |
| CVE-2019-12470 | — | — | 1.4% | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed log in RevisionDelete page is exposed. Fixed... |
| CVE-2019-12469 | — | — | 1.4% | Jul 10, 2019 | MediaWiki through 1.32.1 has Incorrect Access Control. Suppressed username or log in Special:EditTags are exposed. Fixed... |
| CVE-2019-12474 | — | — | 2.0% | Jul 10, 2019 | Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recen... |
| CVE-2019-12473 | — | — | 2.3% | Jul 10, 2019 | Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by queryi... |
| CVE-2019-12472 | — | — | 1.4% | Jul 10, 2019 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.18.0 through 1.32.1. It is possible to bypa... |
| CVE-2019-12471 | — | — | 1.3% | Jul 10, 2019 | Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to ... |
| CVE-2019-12466 | — | — | 0.8% | Jul 10, 2019 | Wikimedia MediaWiki through 1.32.1 allows CSRF. |
| CVE-2019-12468 | — | — | 3.4% | Jul 10, 2019 | An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Sp... |
| CVE-2019-12467 | — | — | 1.3% | Jul 10, 2019 | MediaWiki through 1.32.1 has Incorrect Access Control (issue 1 of 3). A spammer can use Special:ChangeEmail to send out ... |
| CVE-2019-13396 | — | — | 62.6% | Jul 10, 2019 | FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in... |
| CVE-2019-13240 | — | — | 1.7% | Jul 10, 2019 | An issue was discovered in GLPI before 9.4.1. After a successful password reset by a user, it is possible to change that... |
| CVE-2019-10653 | — | — | 1.5% | Jul 10, 2019 | An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page. |
| CVE-2019-12723 | — | — | 2.0% | Jul 10, 2019 | An issue was discovered in the Teclib Fields plugin through 1.9.2 for GLPI. it allows SQL Injection via container_id and... |
| CVE-2019-10122 | — | — | 4.1% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.9 and CCU3 devices before 3.43.16 have buffer overflows in the ReGa ise GmbH HTT... |
| CVE-2019-10121 | — | — | 4.6% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.15 use session IDs for authentication but lack au... |
| CVE-2019-10120 | — | — | 1.3% | Jul 10, 2019 | On eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16, automatic login configuration (aka setAuto... |
| CVE-2019-10119 | — | — | 2.0% | Jul 10, 2019 | eQ-3 HomeMatic CCU2 devices before 2.41.8 and CCU3 devices before 3.43.16 use session IDs for authentication but lack au... |
| CVE-2019-13475 | — | — | 4.1% | Jul 9, 2019 | In MobaXterm 11.1, the mobaxterm: URI handler has an argument injection vulnerability that allows remote attackers to ex... |
| CVE-2019-13472 | — | — | 0.8% | Jul 9, 2019 | PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file. |
| CVE-2019-9150 | — | — | 1.4% | Jul 9, 2019 | Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now