2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-5982Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to cond...
CVE-2019-5981Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary exe...
CVE-2019-5974Cross-site request forgery (CSRF) vulnerability in Contest Gallery versions prior to 10.4.5 allows remote attackers to h...
CVE-2019-5971Cross-site request forgery (CSRF) vulnerability in Attendance Manager 0.5.6 and earlier allows remote attackers to hijac...
CVE-2019-5969Open redirect vulnerability in GROWI v3.4.6 and earlier allows remote attackersto redirect users to arbitrary web sites ...
CVE-2019-5968Cross-site request forgery (CSRF) vulnerability in GROWI v3.4.6 and earlier allows remote attackers to hijack the authen...
CVE-2019-5967Cross-site scripting vulnerability in Joruri CMS 2017 Release2 and earlier allows remote attackers to inject arbitrary w...
CVE-2019-5966Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitra...
CVE-2019-5965Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web ...
CVE-2019-5964iDoors Reader 2.10.17 and earlier allows an attacker on the same network segment to bypass authentication to access the ...
CVE-2019-5961The Android App 'Tootdon for Mastodon' version 3.4.1 and earlier does not verify X.509 certificates from SSL servers, wh...
CVE-2019-5960Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the...
CVE-2019-13314virt-bootstrap 1.1.0 allows local users to discover a root password by listing a process, because this password may be p...
CVE-2019-13312block_cmp() in libavcodec/zmbvenc.c in FFmpeg 4.1.3 has a heap-based buffer over-read.
CVE-2019-13294AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session cont...
CVE-2019-13292A SQL Injection issue was discovered in webERP 4.15. Payments.php accepts payment data in base64 format. After this is d...
CVE-2019-13291In Xpdf 4.01.01, there is a heap-based buffer over-read in the function DCTStream::readScan() located at Stream.cc. It c...
CVE-2019-13290Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing ...
CVE-2019-13289In Xpdf 4.01.01, there is a use-after-free vulnerability in the function JBIG2Stream::close() located at JBIG2Stream.cc....
CVE-2019-13288In Xpdf 4.01.01, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote at...
CVE-2019-13287In Xpdf 4.01.01, there is an out-of-bounds read vulnerability in the function SplashXPath::strokeAdjust() located at spl...
CVE-2019-13275An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the A...
CVE-2019-13262XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x00000000003283eb.
CVE-2019-13261XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000328384.
CVE-2019-13260XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000327a07.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now