2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12171 | — | — | 0.9% | Jul 8, 2019 | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext... |
| CVE-2019-13404 | — | — | 1.3% | Jul 8, 2019 | The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for ... |
| CVE-2019-13402 | — | — | 1.5% | Jul 8, 2019 | /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices ... |
| CVE-2019-13401 | — | — | 0.6% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. |
| CVE-2019-13400 | — | — | 1.6% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. ... |
| CVE-2019-13399 | — | — | 1.1% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices have a hard-coded SSL/TLS key that is used during an administrator's SSL conversatio... |
| CVE-2019-13398 | — | — | 4.1% | Jul 8, 2019 | Dynacolor FCM-MB40 v1.2.0.0 devices allow remote attackers to execute arbitrary commands via a crafted parameter to a CG... |
| CVE-2019-13391 | — | — | 2.8% | Jul 7, 2019 | In ImageMagick 7.0.8-50 Q16, ComplexImages in MagickCore/fourier.c has a heap-based buffer over-read because of incorrec... |
| CVE-2019-13390 | — | — | 1.7% | Jul 7, 2019 | In FFmpeg 4.1.3, there is a division by zero at adx_write_trailer in libavformat/rawenc.c. |
| CVE-2019-13379 | — | — | 3.0% | Jul 7, 2019 | On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privile... |
| CVE-2019-13183 | — | — | 0.8% | Jul 7, 2019 | Flarum before 0.1.0-beta.9 allows CSRF against all POST endpoints, as demonstrated by changing admin settings. |
| CVE-2019-13375 | — | — | 28.2% | Jul 6, 2019 | A SQL Injection was discovered in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 in PayAction.class.php wi... |
| CVE-2019-13374 | — | — | 2.4% | Jul 6, 2019 | A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(10... |
| CVE-2019-13373 | — | — | 68.0% | Jul 6, 2019 | An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validate... |
| CVE-2019-13362 | — | — | 1.0% | Jul 6, 2019 | Codedoc v3.2 has a stack-based buffer overflow in add_variable in codedoc.c, related to codedoc_strlcpy. |
| CVE-2019-10639 | — | — | 3.3% | Jul 5, 2019 | The Linux kernel 4.x (starting from 4.1) and 5.x before 5.0.8 allows Information Exposure (partial kernel address disclo... |
| CVE-2019-10638 | — | — | 2.6% | Jul 5, 2019 | In the Linux kernel before 5.1.7, a device can be tracked by an attacker using the IP ID values the kernel produces for ... |
| CVE-2019-13352 | — | — | 2.9% | Jul 5, 2019 | WolfVision Cynap before 1.30j uses a static, hard-coded cryptographic secret for generating support PINs for the 'forgot... |
| CVE-2019-13351 | — | — | 1.7% | Jul 5, 2019 | posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "... |
| CVE-2019-12971 | — | — | 2.2% | Jul 5, 2019 | BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type. |
| CVE-2019-13345 | — | — | 74.5% | Jul 5, 2019 | The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter. |
| CVE-2019-13344 | — | — | 45.1% | Jul 5, 2019 | An authentication bypass vulnerability in the CRUDLab WP Like Button plugin through 1.6.0 for WordPress allows unauthent... |
| CVE-2019-13341 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/conf.php (comment box), which can be used to get a user's cookie. |
| CVE-2019-13340 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a us... |
| CVE-2019-13339 | — | — | 0.6% | Jul 5, 2019 | In MiniCMS V1.10, stored XSS was found in mc-admin/page-edit.php (content box), which can be used to get a user's cookie... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now