2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-20199MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_decode, while parsing a crafted XML file, perfo...
CVE-2019-20198MEDIUM6.5An issue was discovered in ezXML 0.8.3 through 0.8.6. The function ezxml_ent_ok() mishandles recursion, leading to stack...
CVE-2019-18568HIGH8.8Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a...
CVE-2019-20197HIGH8.8In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id pa...
CVE-2019-3984CRITICAL9.8Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due ...
CVE-2019-14466MEDIUM6.5The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote ...
CVE-2019-10227MEDIUM6.1openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
CVE-2019-9668HIGH7.5An issue was discovered in rovinbhandari FTP through 2012-03-28. receive_file in file_transfer_functions.c allows remote...
CVE-2019-9556MEDIUM5.4FiberHome an5506-04-f RP2669 devices have XSS.
CVE-2019-9554MEDIUM6.1In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at...
CVE-2019-9553MEDIUM6.1Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and ...
CVE-2019-9207MEDIUM6.1PRTG Network Monitor v7.1.3.3378 allows XSS via the /search.htm searchtext parameter. NOTE: This product is discontinued...
CVE-2019-9206MEDIUM6.1PRTG Network Monitor v7.1.3.3378 allows XSS via the /public/login.htm errormsg or loginurl parameter. NOTE: This product...
CVE-2019-9197HIGH8.8The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
CVE-2019-7751HIGH7.5A directory traversal and local file inclusion vulnerability in FPProducerInternetServer.exe in Ricoh MarcomCentral, for...
CVE-2019-12837MEDIUM4.3The Java API in accesuniversitat.gencat.cat 1.7.5 allows remote attackers to get personal information of all registered ...
CVE-2019-7162CRITICAL9.1An issue was discovered in Zoho ManageEngine ADSelfService Plus 5.6 Build 5607. An exposed service allows an unauthentic...
CVE-2019-20176HIGH7.5In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
CVE-2019-12273MEDIUM6.5OutSystems Platform 10 through 11 allows ImageResourceDetail.aspx CSRF for content modifications and file uploads. NOTE:...
CVE-2019-12186MEDIUM4.8An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x thro...
CVE-2019-10229HIGH8.8An issue was discovered in MailStore Server (and Service Provider Edition) 9.x through 11.x before 11.2.2. When the dire...
CVE-2019-20175HIGH7.5An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2.0. The guest system can crash the QEM...
CVE-2019-20172HIGH7.8Kernel/VM/MemoryManager.cpp in SerenityOS before 2019-12-30 does not reject syscalls with pointers into the kernel-only ...
CVE-2019-7479HIGH7.2A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulne...
CVE-2019-19927MEDIUM6In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesys...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now