2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7218 | — | — | 1.2% | May 13, 2019 | Citrix ShareFile before 19.23 allows a downgrade from two-factor authentication to one-factor authentication. An attacke... |
| CVE-2019-7217 | — | — | 2.0% | May 13, 2019 | Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on differe... |
| CVE-2019-11680 | — | — | 4.2% | May 13, 2019 | KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image. |
| CVE-2019-9727 | — | — | 2.2% | May 13, 2019 | Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier all... |
| CVE-2019-9726 | — | — | 15.7% | May 13, 2019 | Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read ... |
| CVE-2019-8342 | — | — | 0.5% | May 13, 2019 | A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorr... |
| CVE-2019-3702 | — | — | 5.3% | May 13, 2019 | A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated a... |
| CVE-2019-7690 | — | — | 3.2% | May 13, 2019 | In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from proce... |
| CVE-2019-12047 | — | — | 1.2% | May 13, 2019 | Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution... |
| CVE-2019-11429 | — | — | 5.9% | May 13, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)... |
| CVE-2019-7411 | — | — | 0.9% | May 13, 2019 | Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authentic... |
| CVE-2019-7409 | — | — | 1.1% | May 13, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbi... |
| CVE-2019-7404 | — | — | 1.5% | May 13, 2019 | An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file v... |
| CVE-2019-12043 | — | — | 0.9% | May 13, 2019 | In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintabl... |
| CVE-2019-11888 | — | — | 2.7% | May 13, 2019 | Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi... |
| CVE-2019-11886 | — | — | 1.9% | May 13, 2019 | The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all... |
| CVE-2019-11885 | — | — | 0.4% | May 12, 2019 | eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr... |
| CVE-2019-5437 | — | — | 1.3% | May 10, 2019 | Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i... |
| CVE-2019-5677 | — | — | 0.3% | May 10, 2019 | NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ... |
| CVE-2019-5675 | — | — | 0.4% | May 10, 2019 | NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ... |
| CVE-2019-5496 | — | — | 0.7% | May 10, 2019 | Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an ... |
| CVE-2019-5495 | — | — | 1.4% | May 10, 2019 | OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security heade... |
| CVE-2019-11066 | — | — | 1.5% | May 10, 2019 | openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method... |
| CVE-2019-11059 | — | — | 1.9% | May 10, 2019 | Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow. |
| CVE-2019-5494 | — | — | 0.7% | May 10, 2019 | OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now