2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-14304 | HIGH | 8.8 | 0.7% | Jan 10, 2020 | Ricoh SP C250DN 1.06 devices allow CSRF. |
| CVE-2019-14302 | MEDIUM | 6.8 | 0.4% | Jan 10, 2020 | On Ricoh SP C250DN 1.06 devices, a debug port can be used. |
| CVE-2019-14301 | HIGH | 7.5 | 1.4% | Jan 10, 2020 | Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2). |
| CVE-2019-19820 | HIGH | 7.8 | 0.7% | Jan 10, 2020 | An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an ... |
| CVE-2019-4559 | MEDIUM | 5.3 | 1.1% | Jan 10, 2020 | IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used t... |
| CVE-2019-4508 | HIGH | 7.8 | 0.3% | Jan 10, 2020 | IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local a... |
| CVE-2019-20376 | MEDIUM | 6.1 | 0.8% | Jan 10, 2020 | A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar... |
| CVE-2019-20375 | MEDIUM | 6.1 | 0.8% | Jan 10, 2020 | A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar... |
| CVE-2019-20374 | CRITICAL | 9.6 | 2.3% | Jan 9, 2020 | A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to R... |
| CVE-2019-20373 | HIGH | 7.8 | 0.4% | Jan 9, 2020 | LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the ... |
| CVE-2019-5209 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-5208 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-5207 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-5206 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-5205 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-20184 | HIGH | 7.8 | 1.6% | Jan 9, 2020 | KeePass 2.4.1 allows CSV injection in the title field of a CSV export. |
| CVE-2019-20183 | HIGH | 7.2 | 6.7% | Jan 9, 2020 | uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension ... |
| CVE-2019-20182 | MEDIUM | 4.8 | 0.7% | Jan 9, 2020 | The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter. |
| CVE-2019-20181 | MEDIUM | 4.8 | 0.7% | Jan 9, 2020 | The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter. |
| CVE-2019-20179 | HIGH | 8.8 | 1.0% | Jan 9, 2020 | SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter. |
| CVE-2019-20178 | MEDIUM | 6.5 | 0.4% | Jan 9, 2020 | Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user. |
| CVE-2019-18970 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18969 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18968 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-18967 | — | — | — | Jan 9, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now