2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-9150——Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality ...
CVE-2019-9147——Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is inte...
CVE-2019-13470——MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
CVE-2019-13380——KEYNTO Team Password Manager 1.5.0 allows XSS because data saved from websites is mishandled in the online vault.
CVE-2019-13277——TRENDnet TEW-827DRU with firmware up to and including 2.04B03 allows an unauthenticated attacker to execute setup wizard...
CVE-2019-11512——Contao 4.x allows SQL Injection. Fixed in Contao 4.4.39 and Contao 4.7.5.
CVE-2019-13338——In WESEEK GROWI before 3.5.0, a remote attacker can obtain the password hash of the creator of a page by leveraging wiki...
CVE-2019-13337——In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL parameter access_token ...
CVE-2019-5044——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-13464——An issue was discovered in OWASP ModSecurity Core Rule Set (CRS) 3.0.2. Use of X.Filename instead of X_Filename can bypa...
CVE-2019-13280——TRENDnet TEW-827DRU with firmware up to and including 2.04B03 contains a stack-based buffer overflow while returning an ...
CVE-2019-13070——A stored XSS vulnerability in the Agent/Center component of CyberPower PowerPanel Business Edition 3.4.0 allows a privil...
CVE-2019-11991——HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processo...
CVE-2019-8920——iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
CVE-2019-3950——Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows roo...
CVE-2019-3949——Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to ...
CVE-2019-13461——In PrestaShop before 1.7.6.0 RC2, the id_address_delivery and id_address_invoice parameters are affected by an Insecure ...
CVE-2019-13146——The field_test gem 0.3.0 for Ruby has unvalidated input. A method call that is expected to return a value from a certain...
CVE-2019-13142——The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user...
CVE-2019-13397——Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary w...
CVE-2019-12782——An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 (before 5.1.2) allows a low...
CVE-2019-11890——Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood...
CVE-2019-11889——Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page ov...
CVE-2019-13450——In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a v...
CVE-2019-13449——In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a s...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now