2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2019-16164MEDIUM6.5MyHTML through 4.0.5 has a NULL pointer dereference in myhtml_tree_node_remove in tree.c.
CVE-2019-10670MEDIUM6.1An issue was discovered in LibreNMS through 1.47. Many of the scripts rely on the function mysqli_escape_real_string for...
CVE-2019-16148MEDIUM6.1Sakai through 12.6 allows XSS via a chat user name.
CVE-2019-16146MEDIUM4.8Gophish through 0.8.0 allows XSS via a username.
CVE-2019-10667MEDIUM5.3An issue was discovered in LibreNMS through 1.47. Information disclosure can occur: an attacker can fingerprint the exac...
CVE-2019-16133MEDIUM6.5An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwor...
CVE-2019-16132MEDIUM6.5An issue was discovered in OKLite v1.2.25. framework/admin/tpl_control.php allows remote attackers to delete arbitrary f...
CVE-2019-16130MEDIUM6.1YII2-CMS v1.0 has XSS in protected\core\modules\home\models\Contact.php via a name field to /contact.html.
CVE-2019-16126MEDIUM6.1Grav through 1.6.15 allows (Stored) Cross-Site Scripting due to JavaScript execution in SVG images.
CVE-2019-16118MEDIUM6.1Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi...
CVE-2019-16117MEDIUM6.1Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi...
CVE-2019-16109MEDIUM5.3An issue was discovered in Plataformatec Devise before 4.7.1. It confirms accounts upon receiving a request with a blank...
CVE-2019-16104MEDIUM6.1Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
CVE-2019-16097MEDIUM6.5core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users A...
CVE-2019-16089MEDIUM4.1An issue was discovered in the Linux kernel through 5.2.13. nbd_genl_status in drivers/block/nbd.c does not check the nl...
CVE-2019-9461MEDIUM6.5In the Android kernel in VPN routing there is a possible information disclosure. This could lead to remote information d...
CVE-2019-9456MEDIUM6.7In the Android kernel in Pixel C USB monitor driver there is a possible OOB write due to a missing bounds check. This co...
CVE-2019-9454MEDIUM6.7In the Android kernel in i2c driver there is a possible out of bounds write due to memory corruption. This could lead to...
CVE-2019-9453MEDIUM4.4In the Android kernel in F2FS touch driver there is a possible out of bounds read due to improper input validation. This...
CVE-2019-9452MEDIUM4.4In the Android kernel in SEC_TS touch driver there is a possible out of bounds read due to a missing bounds check. This ...
CVE-2019-9451MEDIUM6.7In the Android kernel in the touchscreen driver there is a possible out of bounds write due to a missing bounds check. T...
CVE-2019-9450MEDIUM6.4In the Android kernel in the FingerTipS touchscreen driver there is a possible memory corruption due to a race condition...
CVE-2019-9445MEDIUM4.4In the Android kernel in F2FS driver there is a possible out of bounds read due to a missing bounds check. This could le...
CVE-2019-9443MEDIUM6.7In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This cou...
CVE-2019-9442MEDIUM6.7In the Android kernel in the mnh driver there is possible memory corruption due to a use after free. This could lead to ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now