2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-2244——Possible integer underflow can happen when calculating length of elementary stream info from invalid section length whic...
CVE-2019-11604——An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notso...
CVE-2019-10848——Computrols CBAS 18.0.0 allows Username Enumeration.
CVE-2019-10847——Computrols CBAS 18.0.0 allows Cross-Site Request Forgery.
CVE-2019-12315——Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "...
CVE-2019-12195——TP-Link TL-WR840N v5 00000005 devices allow XSS via the network name. The attacker must log into the router by breaking ...
CVE-2019-12155——interface_release_resource in hw/display/qxl.c in QEMU 3.1.x through 4.0.0 has a NULL pointer dereference.
CVE-2019-12150——Karamasoft UltimateEditor 1 does not ensure that an uploaded file is an image or document (neither file types nor extens...
CVE-2019-11876——In PrestaShop 1.7.5.2, the shop_country parameter in the install/index.php installation script/component is affected by ...
CVE-2019-11875——In AutomateAppCore.dll in Blue Prism Robotic Process Automation 6.4.0.8445, a vulnerability in access control can be exp...
CVE-2019-12314——Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as ...
CVE-2019-12313——XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
CVE-2019-12312——In Libreswan 3.27 an assertion failure can lead to a pluto IKE daemon restart. An attacker can trigger a NULL pointer de...
CVE-2019-12309——dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerabilit...
CVE-2019-10850——Computrols CBAS 18.0.0 has Default Credentials.
CVE-2019-10849——Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
CVE-2019-10866——In the Form Maker plugin before 1.13.3 for WordPress, it's possible to achieve SQL injection in the function get_labels_...
CVE-2019-10855——Computrols CBAS 18.0.0 mishandles password hashes. The approach is MD5 with a pw prefix, e.g., if the password is admin,...
CVE-2019-10854——Computrols CBAS 18.0.0 allows Authenticated Command Injection.
CVE-2019-10853——Computrols CBAS 18.0.0 allows Authentication Bypass.
CVE-2019-10852——Computrols CBAS 18.0.0 allows Authenticated Blind SQL Injection via the id GET parameter, as demonstrated by the index.p...
CVE-2019-10851——Computrols CBAS 18.0.0 has hard-coded encryption keys.
CVE-2019-7128——Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7127——Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...
CVE-2019-7124——Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier ver...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now