2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-14304HIGH8.8Ricoh SP C250DN 1.06 devices allow CSRF.
CVE-2019-14302MEDIUM6.8On Ricoh SP C250DN 1.06 devices, a debug port can be used.
CVE-2019-14301HIGH7.5Ricoh SP C250DN 1.06 devices have Incorrect Access Control (issue 1 of 2).
CVE-2019-19820HIGH7.8An invalid pointer vulnerability in IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an ...
CVE-2019-4559MEDIUM5.3IBM QRadar SIEM 7.3.0 through 7.3.3 discloses sensitive information to unauthorized users. The information can be used t...
CVE-2019-4508HIGH7.8IBM QRadar SIEM 7.3.0 through 7.3.3 uses weak credential storage in some instances which could be decrypted by a local a...
CVE-2019-20376MEDIUM6.1A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar...
CVE-2019-20375MEDIUM6.1A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrar...
CVE-2019-20374CRITICAL9.6A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to R...
CVE-2019-20373HIGH7.8LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the ...
CVE-2019-5209Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-5208Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-5207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-5206Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-5205Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-20184HIGH7.8KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
CVE-2019-20183HIGH7.2uploadimage.php in Employee Records System 1.0 allows upload and execution of arbitrary PHP code because file-extension ...
CVE-2019-20182MEDIUM4.8The FooGallery plugin 1.8.12 for WordPress allow XSS via the post_title parameter.
CVE-2019-20181MEDIUM4.8The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
CVE-2019-20179HIGH8.8SOPlanning 1.45 has SQL injection via the user_list.php "by" parameter.
CVE-2019-20178MEDIUM6.5Advisto PEEL Shopping 9.2.1 has CSRF via administrer/utilisateurs.php to delete a user.
CVE-2019-18970Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18969Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18968Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-18967Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now