2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-9147Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is inte...
CVE-2019-13470MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
CVE-2019-13380KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
CVE-2019-13277TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard...
CVE-2019-11512Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
CVE-2019-13338In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki...
CVE-2019-13337In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token ...
CVE-2019-5044Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13464An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypa...
CVE-2019-13280TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an ...
CVE-2019-13070A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privil...
CVE-2019-11991HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processo...
CVE-2019-8920iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVE-2019-3950Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows roo...
CVE-2019-3949Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to ...
CVE-2019-13461In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure ...
CVE-2019-13146The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain...
CVE-2019-13142The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user...
CVE-2019-13397Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary w...
CVE-2019-12782An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low...
CVE-2019-11890Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood...
CVE-2019-11889Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page ov...
CVE-2019-13450In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a v...
CVE-2019-13449In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a s...
CVE-2019-13369Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now