2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-9105——The WebApp v04.68 in the supervisor on SAET Impianti Speciali TEBE Small 05.01 build 1137 devices allows remote attacker...
CVE-2019-6725——The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. Afte...
CVE-2019-5678——NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attac...
CVE-2019-10123——SQL Injection in Advanced InfoData Systems (AIS) ESEL-Server 67 (which is the backend for the AIS logistics mobile app) ...
CVE-2019-10069——In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
CVE-2019-10049——It is possible for an attacker with regular user access to the web application of Pydio through 8.2.2 to trick an admini...
CVE-2019-10048——The ImageMagick plugin that is installed by default in Pydio through 8.2.2 does not perform the appropriate validation a...
CVE-2019-10047——A stored XSS vulnerability exists in the web application of Pydio through 8.2.2 that can be exploited by levering the fi...
CVE-2019-10046——An unauthenticated attacker can obtain information about the Pydio 8.2.2 configuration including session timeout, librar...
CVE-2019-10045——The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the respons...
CVE-2019-10038——Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file...
CVE-2019-9891——The function getopt_simple as described in Advanced Bash Scripting Guide (ISBN 978-1435752184) allows privilege escalati...
CVE-2019-9871——Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.
CVE-2019-10328——Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attac...
CVE-2019-10327——An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed atta...
CVE-2019-10326——A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset wa...
CVE-2019-10325——A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure...
CVE-2019-10324——A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ReleaseAction#doSubmit, Gr...
CVE-2019-10321——A cross-site request forgery vulnerability in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.Descrip...
CVE-2019-12507——An XSS vulnerability exists in PHPRelativePath (aka Relative Path) through 1.0.2 via the RelativePath.Example1.php path ...
CVE-2019-12502——There is a lack of CSRF countermeasures on MOBOTIX S14 MX-V4.2.1.61 cameras, as demonstrated by adding an admin account ...
CVE-2019-12500——The Xiaomi M365 scooter 2019-02-12 before 1.5.1 allows spoofing of "suddenly accelerate" commands. This occurs because B...
CVE-2019-12499——Firejail before 0.9.60 allows truncation (resizing to length 0) of the firejail binary on the host by running exploit co...
CVE-2019-12495——An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-by...
CVE-2019-12493——A stack-based buffer over-read exists in PostScriptFunction::transform in Function.cc in Xpdf 4.01.01 because GfxSeparat...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now