2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12145 | — | — | 4.7% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An ... |
| CVE-2019-12144 | — | — | 2.9% | Jun 11, 2019 | An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the abi... |
| CVE-2019-12143 | — | — | 2.0% | Jun 11, 2019 | A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An ... |
| CVE-2019-0220 | — | — | 17.9% | Jun 11, 2019 | A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multi... |
| CVE-2019-12794 | — | — | 0.9% | Jun 11, 2019 | An issue was discovered in MISP 2.4.108. Organization admins could reset credentials for site admins (organization admin... |
| CVE-2019-10338 | — | — | 1.0% | Jun 11, 2019 | A cross-site request forgery vulnerability in Jenkins JX Resources Plugin 1.0.36 and earlier in GlobalPluginConfiguratio... |
| CVE-2019-10337 | — | — | 2.0% | Jun 11, 2019 | An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to con... |
| CVE-2019-10336 | — | — | 1.4% | Jun 11, 2019 | A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able t... |
| CVE-2019-10335 | — | — | 1.1% | Jun 11, 2019 | A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to c... |
| CVE-2019-10334 | — | — | 1.3% | Jun 11, 2019 | Jenkins ElectricFlow Plugin 1.1.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master... |
| CVE-2019-10331 | — | — | 1.1% | Jun 11, 2019 | A cross-site request forgery vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConne... |
| CVE-2019-10226 | — | — | 4.7% | Jun 10, 2019 | HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to th... |
| CVE-2019-11881 | — | — | 2.3% | Jun 10, 2019 | A vulnerability exists in Rancher before 2.2.4 in the login component, where the errorMsg parameter can be tampered to d... |
| CVE-2019-12790 | — | — | 1.7% | Jun 10, 2019 | In radare2 through 3.5.1, there is a heap-based buffer over-read in the r_egg_lang_parsechar function of egg_lang.c. Thi... |
| CVE-2019-11027 | — | — | 2.9% | Jun 10, 2019 | Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw. This library is used by Rails web applicati... |
| CVE-2019-9881 | — | — | 18.8% | Jun 10, 2019 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on ... |
| CVE-2019-9880 | — | — | 34.8% | Jun 10, 2019 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, ... |
| CVE-2019-9879 | — | — | 46.6% | Jun 10, 2019 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever ... |
| CVE-2019-11517 | — | — | 0.4% | Jun 10, 2019 | WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-201... |
| CVE-2019-6241 | — | — | 1.1% | Jun 10, 2019 | In Bevywise MQTTRoute 1.1 build 1018-002, a connect packet combined with a malformed unsubscribe request packet can be u... |
| CVE-2019-11877 | — | — | 0.9% | Jun 10, 2019 | XSS on the PIX-Link Repeater/Router LV-WR09 with firmware v28K.MiniRouter.20180616 allows attackers to steal credentials... |
| CVE-2019-12780 | — | — | 72.0% | Jun 10, 2019 | The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS... |
| CVE-2019-5243 | — | — | 0.6% | Jun 10, 2019 | There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect th... |
| CVE-2019-0209 | — | — | — | Jun 10, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-9087 | — | — | 1.6% | Jun 7, 2019 | HotelDruid before v2.3.1 has SQL Injection via the /tab_tariffe.php numtariffa1 parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now