2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16713 | MEDIUM | 6.5 | 2.5% | Sep 23, 2019 | ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c. |
| CVE-2019-16712 | MEDIUM | 6.5 | 2.6% | Sep 23, 2019 | ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image. |
| CVE-2019-16711 | MEDIUM | 6.5 | 2.5% | Sep 23, 2019 | ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c. |
| CVE-2019-16710 | MEDIUM | 6.5 | 2.5% | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c. |
| CVE-2019-16709 | MEDIUM | 6.5 | 2.8% | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. |
| CVE-2019-16708 | MEDIUM | 6.5 | 2.5% | Sep 23, 2019 | ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage. |
| CVE-2019-16707 | MEDIUM | 6.5 | 1.7% | Sep 23, 2019 | Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx. |
| CVE-2019-16704 | MEDIUM | 4.8 | 0.8% | Sep 23, 2019 | admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS. |
| CVE-2019-16703 | MEDIUM | 6.1 | 0.8% | Sep 23, 2019 | admin/infolist_add.php in PHPMyWind 5.6 has stored XSS. |
| CVE-2019-16681 | MEDIUM | 4.7 | 0.7% | Sep 21, 2019 | The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to t... |
| CVE-2019-16680 | MEDIUM | 4.3 | 2.1% | Sep 21, 2019 | An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename cont... |
| CVE-2019-16679 | MEDIUM | 4.9 | 7.0% | Sep 21, 2019 | Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion. |
| CVE-2019-16678 | MEDIUM | 6.5 | 0.7% | Sep 21, 2019 | admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route. |
| CVE-2019-16677 | MEDIUM | 6.5 | 0.5% | Sep 21, 2019 | An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. |
| CVE-2019-16669 | MEDIUM | 5.3 | 1.1% | Sep 21, 2019 | The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a val... |
| CVE-2019-16665 | MEDIUM | 6.1 | 0.7% | Sep 21, 2019 | An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1... |
| CVE-2019-16664 | MEDIUM | 4.8 | 0.6% | Sep 21, 2019 | An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter. |
| CVE-2019-16661 | MEDIUM | 5.4 | 0.6% | Sep 21, 2019 | Ogma CMS 0.5 has XSS via creation of a new blog. |
| CVE-2019-16657 | MEDIUM | 6.1 | 0.7% | Sep 21, 2019 | TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/. |
| CVE-2019-6145 | MEDIUM | 6.7 | 0.7% | Sep 20, 2019 | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables loc... |
| CVE-2019-11327 | MEDIUM | 4.9 | 1.4% | Sep 20, 2019 | An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the... |
| CVE-2019-4505 | MEDIUM | 5.3 | 2.4% | Sep 20, 2019 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensi... |
| CVE-2019-16643 | MEDIUM | 5.4 | 0.6% | Sep 20, 2019 | An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area. |
| CVE-2019-16534 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE:... |
| CVE-2019-16533 | MEDIUM | 6.1 | 0.8% | Sep 20, 2019 | On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now