2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-6971——An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe...
CVE-2019-10257——Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restr...
CVE-2019-12436——Samba 4.10.x before 4.10.5 has a NULL pointer dereference, leading to an AD DC LDAP server Denial of Service. This is re...
CVE-2019-12435——Samba 4.9.x before 4.9.9 and 4.10.x before 4.10.5 has a NULL pointer dereference, leading to Denial of Service. This is ...
CVE-2019-3954——Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi...
CVE-2019-10085——In Apache Allura prior to 1.11.0, a vulnerability exists for stored XSS on the user dropdown selector when creating or e...
CVE-2019-3953——Stack-based buffer overflow in Advantech WebAccess/SCADA 8.4.0 allows a remote, unauthenticated attacker to execute arbi...
CVE-2019-12133——Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDR...
CVE-2019-12592——A universal Cross-site scripting (UXSS) vulnerability in the Evernote Web Clipper extension before 7.11.1 for Chrome all...
CVE-2019-12875——Alpine Linux abuild through 3.4.0 allows an unprivileged member of the abuild group to add an untrusted package via a --...
CVE-2019-12874——An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through ...
CVE-2019-12872——dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view...
CVE-2019-7159——OX App Suite 7.10.1 and earlier allows Information Exposure.
CVE-2019-6965——An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.
CVE-2019-10998——An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.10465...
CVE-2019-12868——app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exist...
CVE-2019-12865——In radare2 through 3.5.1, cmd_mount in libr/core/cmd_mount.c has a double free for the ms command.
CVE-2019-7158——OX App Suite 7.10.0 and earlier has Incorrect Access Control.
CVE-2019-7579——An issue was discovered on Linksys WRT1900ACS 1.0.3.187766 devices. An ability exists for an unauthenticated user to bro...
CVE-2019-7315——Genie Access WIP3BVAF WISH IP 3MP IR Auto Focus Bullet Camera devices through 3.x are vulnerable to directory traversal ...
CVE-2019-11410——app/backup/index.php in the Backup Module in FusionPBX 4.4.3 suffers from a command injection vulnerability due to a lac...
CVE-2019-12801——out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Nam...
CVE-2019-12476——An authentication bypass vulnerability in the password reset functionality in Zoho ManageEngine ADSelfService Plus befor...
CVE-2019-11408——XSS in app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 allows remote unauthenticated at...
CVE-2019-11407——app/operator_panel/index_inc.php in the Operator Panel module in FusionPBX 4.4.3 suffers from an information disclosure ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now