2019 CVE Vulnerabilities

17,619 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16713MEDIUM6.5ImageMagick 7.0.8-43 has a memory leak in coders/dot.c, as demonstrated by PingImage in MagickCore/constitute.c.
CVE-2019-16712MEDIUM6.5ImageMagick 7.0.8-43 has a memory leak in Huffman2DEncodeImage in coders/ps3.c, as demonstrated by WritePS3Image.
CVE-2019-16711MEDIUM6.5ImageMagick 7.0.8-40 has a memory leak in Huffman2DEncodeImage in coders/ps2.c.
CVE-2019-16710MEDIUM6.5ImageMagick 7.0.8-35 has a memory leak in coders/dot.c, as demonstrated by AcquireMagickMemory in MagickCore/memory.c.
CVE-2019-16709MEDIUM6.5ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage.
CVE-2019-16708MEDIUM6.5ImageMagick 7.0.8-35 has a memory leak in magick/xwindow.c, related to XCreateImage.
CVE-2019-16707MEDIUM6.5Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.
CVE-2019-16704MEDIUM4.8admin/infoclass_update.php in PHPMyWind 5.6 has stored XSS.
CVE-2019-16703MEDIUM6.1admin/infolist_add.php in PHPMyWind 5.6 has stored XSS.
CVE-2019-16681MEDIUM4.7The Traveloka application 3.14.0 for Android exports com.traveloka.android.activity.common.WebViewActivity, leading to t...
CVE-2019-16680MEDIUM4.3An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename cont...
CVE-2019-16679MEDIUM4.9Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
CVE-2019-16678MEDIUM6.5admin/urlrule/add.html in YzmCMS 5.3 allows CSRF with a resultant denial of service by adding a superseding route.
CVE-2019-16677MEDIUM6.5An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
CVE-2019-16669MEDIUM5.3The Reset Password feature in Pagekit 1.0.17 gives a different response depending on whether the e-mail address of a val...
CVE-2019-16665MEDIUM6.1An issue was discovered in ThinkSAAS 2.91. There is XSS via the content to the index.php?app=group&ac=comment&ts=do&js=1...
CVE-2019-16664MEDIUM4.8An issue was discovered in ThinkSAAS 2.91. There is XSS via the index.php?app=group&ac=create&ts=do groupname parameter.
CVE-2019-16661MEDIUM5.4Ogma CMS 0.5 has XSS via creation of a new blog.
CVE-2019-16657MEDIUM6.1TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
CVE-2019-6145MEDIUM6.7Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables loc...
CVE-2019-11327MEDIUM4.9An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the...
CVE-2019-4505MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Network Deployment could allow a remote attacker to obtain sensi...
CVE-2019-16643MEDIUM5.4An issue was discovered in ZrLog 2.1.1. There is a Stored XSS vulnerability in the article_edit area.
CVE-2019-16534MEDIUM6.1On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE:...
CVE-2019-16533MEDIUM6.1On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now