2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12939 | — | — | 1.4% | Jun 24, 2019 | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter. |
| CVE-2019-12870 | — | — | 3.7% | Jun 24, 2019 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86.... |
| CVE-2019-12869 | — | — | 3.8% | Jun 24, 2019 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86.... |
| CVE-2019-12323 | — | — | 8.8% | Jun 24, 2019 | The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. |
| CVE-2019-12292 | — | — | 1.5% | Jun 24, 2019 | Citrix AppDNA before 7 1906.1.0.472 has Incorrect Access Control. |
| CVE-2019-11648 | — | — | 1.1% | Jun 24, 2019 | An information leakage exists in Micro Focus NetIQ Self Service Password Reset Software all versions prior to version 4.... |
| CVE-2019-11647 | — | — | 0.6% | Jun 24, 2019 | A potential XSS exists in Self Service Password Reset, in Micro Focus NetIQ Software all versions prior to version 4.4. ... |
| CVE-2019-12871 | — | — | 3.7% | Jun 24, 2019 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86.... |
| CVE-2019-12938 | — | — | 1.0% | Jun 24, 2019 | The Roundcube component of Analogic Poste.io 2.1.6 uses .htaccess to protect the logs/ folder, which is effective with t... |
| CVE-2019-12929 | — | — | 4.9% | Jun 24, 2019 | The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which allows the attacker to achi... |
| CVE-2019-12928 | — | — | 23.0% | Jun 24, 2019 | The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection, which allows the remote... |
| CVE-2019-12937 | — | — | 0.5% | Jun 23, 2019 | apps/gsudo.c in gsudo in ToaruOS through 1.10.9 has a buffer overflow allowing local privilege escalation to the root us... |
| CVE-2019-12933 | — | — | — | Jun 22, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11877. Reason: This candidate is a duplicate of ... |
| CVE-2019-10028 | — | — | 1.1% | Jun 21, 2019 | Denial of Service (DOS) in Dial Reference Source Code Used before June 18th, 2019. |
| CVE-2019-11392 | — | — | 1.6% | Jun 21, 2019 | BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. |
| CVE-2019-10719 | — | — | 7.6% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishand... |
| CVE-2019-10718 | — | — | 2.7% | Jun 21, 2019 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Co... |
| CVE-2019-12572 | — | — | 0.9% | Jun 21, 2019 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could... |
| CVE-2019-11011 | — | — | 2.6% | Jun 21, 2019 | Akamai CloudTest before 58.30 allows remote code execution. |
| CVE-2019-10072 | — | — | 73.0% | Jun 21, 2019 | The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomc... |
| CVE-2019-12836 | — | — | 1.0% | Jun 21, 2019 | The Bobronix JEditor editor before 3.0.6 for Jira allows an attacker to add a URL/Link (to an existing issue) that can c... |
| CVE-2019-12920 | — | — | 2.3% | Jun 20, 2019 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to... |
| CVE-2019-12919 | — | — | 0.4% | Jun 20, 2019 | On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthentic... |
| CVE-2019-8459 | — | — | 1.2% | Jun 20, 2019 | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without us... |
| CVE-2019-12745 | — | — | 2.6% | Jun 20, 2019 | out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now