2019 CVE Vulnerabilities
17,619 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10257 | — | — | 2.4% | Jun 19, 2019 | Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restr... |
| CVE-2019-12436 | — | — | 2.8% | Jun 19, 2019 | Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is re... |
| CVE-2019-12435 | — | — | 2.2% | Jun 19, 2019 | Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is ... |
| CVE-2019-3954 | — | — | 3.9% | Jun 19, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-10085 | — | — | 5.1% | Jun 19, 2019 | In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or e... |
| CVE-2019-3953 | — | — | 4.0% | Jun 18, 2019 | Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi... |
| CVE-2019-12133 | — | — | 1.8% | Jun 18, 2019 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDR... |
| CVE-2019-12592 | — | — | 1.1% | Jun 18, 2019 | A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome all... |
| CVE-2019-12875 | — | — | 1.3% | Jun 18, 2019 | Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --... |
| CVE-2019-12874 | — | — | 2.4% | Jun 18, 2019 | An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through ... |
| CVE-2019-12872 | — | — | 1.3% | Jun 18, 2019 | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view... |
| CVE-2019-7159 | — | — | 1.6% | Jun 18, 2019 | OX App Suite 7.10.1 and earlier allows Information Exposure. |
| CVE-2019-6965 | — | — | 2.5% | Jun 18, 2019 | An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter. |
| CVE-2019-10998 | — | — | 0.4% | Jun 18, 2019 | An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465... |
| CVE-2019-12868 | — | — | 3.4% | Jun 18, 2019 | app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exist... |
| CVE-2019-12865 | — | — | 0.9% | Jun 17, 2019 | In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command. |
| CVE-2019-7158 | — | — | 1.5% | Jun 17, 2019 | OX App Suite 7.10.0 and earlier has Incorrect Access Control. |
| CVE-2019-7579 | — | — | 1.8% | Jun 17, 2019 | An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to bro... |
| CVE-2019-7315 | — | — | 11.2% | Jun 17, 2019 | Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal ... |
| CVE-2019-11410 | — | — | 3.4% | Jun 17, 2019 | app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lac... |
| CVE-2019-12801 | — | — | 1.9% | Jun 17, 2019 | out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Nam... |
| CVE-2019-12476 | — | — | 1.5% | Jun 17, 2019 | An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus befor... |
| CVE-2019-11408 | — | — | 6.9% | Jun 17, 2019 | XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated at... |
| CVE-2019-11407 | — | — | 1.5% | Jun 17, 2019 | app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure ... |
| CVE-2019-10997 | — | — | 1.0% | Jun 17, 2019 | An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now