2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7218Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacke...
CVE-2019-7217Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on differe...
CVE-2019-11680KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image.
CVE-2019-9727Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier all...
CVE-2019-9726Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read ...
CVE-2019-8342A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorr...
CVE-2019-3702A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated a...
CVE-2019-7690In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from proce...
CVE-2019-12047Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution...
CVE-2019-11429CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)...
CVE-2019-7411Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authentic...
CVE-2019-7409Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbi...
CVE-2019-7404An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file v...
CVE-2019-12043In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintabl...
CVE-2019-11888Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi...
CVE-2019-11886The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all...
CVE-2019-11885eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr...
CVE-2019-5437Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i...
CVE-2019-5677NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-5675NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-5496Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an ...
CVE-2019-5495OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security heade...
CVE-2019-11066openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method...
CVE-2019-11059Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
CVE-2019-5494OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which c...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now