2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-12373 | — | — | 1.0% | Jun 3, 2019 | Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 ... |
| CVE-2019-12177 | — | — | 1.4% | Jun 3, 2019 | Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0... |
| CVE-2019-12176 | — | — | 0.3% | Jun 3, 2019 | Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows lo... |
| CVE-2019-11370 | — | — | 4.0% | Jun 3, 2019 | Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" f... |
| CVE-2019-11369 | — | — | 7.1% | Jun 3, 2019 | An issue was discovered in Carel pCOWeb prior to B1.2.4. In /config/pw_changeusers.html the device stores cleartext pass... |
| CVE-2019-3567 | — | — | 1.7% | Jun 3, 2019 | In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard l... |
| CVE-2019-12310 | — | — | 3.3% | Jun 3, 2019 | ExaGrid appliances with firmware version v4.8.1.1044.P50 have a /monitor/data/Upgrade/ directory traversal vulnerability... |
| CVE-2019-9883 | — | — | 0.7% | Jun 3, 2019 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to elevate privilege of s... |
| CVE-2019-9882 | — | — | 0.7% | Jun 3, 2019 | Multi modules of MailSherlock MSR35 and MSR45 lead to a CSRF vulnerability. It allows attacker to add malicious email so... |
| CVE-2019-12593 | — | — | 41.0% | Jun 3, 2019 | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index... |
| CVE-2019-12308 | — | — | 2.6% | Jun 3, 2019 | An issue was discovered in Django 1.11 before 1.11.21, 2.1 before 2.1.9, and 2.2 before 2.2.2. The clickable Current URL... |
| CVE-2019-11646 | — | — | 2.5% | Jun 3, 2019 | Remote unauthorized command execution and unauthorized disclosure of information in Micro Focus Service Manager, version... |
| CVE-2019-3397 | — | — | 5.1% | Jun 3, 2019 | Atlassian Bitbucket Data Center licensed instances starting with version 5.13.0 before 5.13.6 (the fixed version for 5.1... |
| CVE-2019-12582 | — | — | — | Jun 3, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-12583. Reason: This candidate is a reservation d... |
| CVE-2019-12589 | — | — | 0.5% | Jun 3, 2019 | In Firejail before 0.9.60, seccomp filters are writable inside the jail, leading to a lack of intended seccomp restricti... |
| CVE-2019-12585 | — | — | 5.0% | Jun 3, 2019 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution iss... |
| CVE-2019-12584 | — | — | 2.6% | Jun 3, 2019 | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php... |
| CVE-2019-12569 | — | — | 15.0% | Jun 3, 2019 | A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a ... |
| CVE-2019-12566 | — | — | 1.1% | Jun 3, 2019 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is ... |
| CVE-2019-12564 | — | — | 2.0% | Jun 3, 2019 | In DouCo DouPHP v1.5 Release 20190516, remote attackers can view the database backup file via a brute-force guessing app... |
| CVE-2019-12530 | — | — | 1.5% | Jun 2, 2019 | Incorrect access control was discovered in the stdonato Dashboard plugin through 0.9.7 for GLPI, affecting df.php, issue... |
| CVE-2019-12515 | — | — | 1.3% | Jun 2, 2019 | There is an out-of-bounds read vulnerability in the function FlateStream::getChar() located at Stream.cc in Xpdf 4.01.01... |
| CVE-2019-9653 | — | — | 11.5% | May 31, 2019 | NUUO Network Video Recorder Firmware 1.7.x through 3.3.x allows unauthenticated attackers to execute arbitrary commands ... |
| CVE-2019-9106 | — | — | 2.8% | May 31, 2019 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attacker... |
| CVE-2019-9105 | — | — | 2.4% | May 31, 2019 | The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attacker... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now