2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-13136 | — | — | 1.5% | Jul 1, 2019 | ImageMagick before 7.0.8-50 has an integer overflow vulnerability in the function TIFFSeekCustomStream in coders/tiff.c. |
| CVE-2019-7668 | — | — | 1.6% | Jul 1, 2019 | Prima Systems FlexAir devices have Default Credentials. |
| CVE-2019-7279 | — | — | 1.8% | Jul 1, 2019 | Optergy Proton/Enterprise devices have Hard-coded Credentials. |
| CVE-2019-1578 | — | — | 1.1% | Jul 1, 2019 | Cross-site scripting vulnerability in Palo Alto Networks MineMeld version 0.9.60 and earlier may allow a remote attacker... |
| CVE-2019-1577 | — | — | 0.9% | Jul 1, 2019 | Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject... |
| CVE-2019-13024 | — | — | 32.2% | Jul 1, 2019 | Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra... |
| CVE-2019-12826 | — | — | 1.1% | Jul 1, 2019 | A Cross-Site-Request-Forgery (CSRF) vulnerability in widget_logic.php in the 2by2host Widget Logic plugin before 5.10.2 ... |
| CVE-2019-13131 | — | — | 3.6% | Jul 1, 2019 | Super Micro SuperDoctor 5, when restrictions are not implemented in agent.cfg, allows remote attackers to execute arbitr... |
| CVE-2019-13129 | — | — | 1.4% | Jul 1, 2019 | On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8... |
| CVE-2019-13128 | — | — | 7.7% | Jul 1, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is a command injection in HNAP1 (exploit... |
| CVE-2019-13127 | — | — | 1.5% | Jul 1, 2019 | An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence ... |
| CVE-2019-13125 | — | — | 1.0% | Jul 1, 2019 | HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation. |
| CVE-2019-12781 | — | — | 1.7% | Jul 1, 2019 | An issue was discovered in Django 1.11 before 1.11.22, 2.1 before 2.1.10, and 2.2 before 2.2.3. An HTTP request is not r... |
| CVE-2019-12970 | — | — | 1.8% | Jul 1, 2019 | XSS was discovered in SquirrelMail through 1.4.22 and 1.5.x through 1.5.2. Due to improper handling of RCDATA and RAWTEX... |
| CVE-2019-13086 | — | — | 32.0% | Jun 30, 2019 | core/MY_Security.php in CSZ CMS 1.2.2 before 2019-06-20 has member/login/check SQL injection by sending a crafted HTTP U... |
| CVE-2019-13085 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000030ecfa. |
| CVE-2019-13084 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x000000000026b739. |
| CVE-2019-13083 | — | — | 1.2% | Jun 30, 2019 | XnView Classic 2.48 has a User Mode Write AV starting at xnview+0x0000000000384e2a. |
| CVE-2019-13082 | — | — | 4.0% | Jun 30, 2019 | Chamilo LMS 1.11.8 and 2.x allows remote code execution through an lp_upload.php unauthenticated file upload feature. It... |
| CVE-2019-13075 | — | — | 1.9% | Jun 30, 2019 | Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's ... |
| CVE-2019-13068 | — | — | 51.9% | Jun 30, 2019 | public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the ... |
| CVE-2019-13067 | — | — | 1.6% | Jun 30, 2019 | njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after t... |
| CVE-2019-13055 | — | — | 1.0% | Jun 29, 2019 | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decr... |
| CVE-2019-13054 | — | — | 0.8% | Jun 29, 2019 | The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Win... |
| CVE-2019-13053 | — | — | 0.5% | Jun 29, 2019 | Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combina... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now