2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7217——Citrix ShareFile before 19.12 allows User Enumeration. It is possible to enumerate application username based on differe...
CVE-2019-11680——KonaKart 8.9.0.0 is vulnerable to Remote Code Execution by uploading a web shell as a product category image.
CVE-2019-9727——Unauthenticated password hash disclosure in the User.getUserPWD method in eQ-3 AG Homematic CCU3 3.43.15 and earlier all...
CVE-2019-9726——Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read ...
CVE-2019-8342——A Local Privilege Escalation in libqcocoa.dylib in Foxit Reader 3.1.0.0111 on macOS has been discovered due to an incorr...
CVE-2019-3702——A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated a...
CVE-2019-7690——In MobaTek MobaXterm Personal Edition v11.1 Build 3860, the SSH private key and its password can be retrieved from proce...
CVE-2019-12047——Gridea v0.8.0 has an XSS vulnerability through which the Nodejs module can be called to achieve arbitrary code execution...
CVE-2019-11429——CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version), 0.9.8.753 (Pro) and 0.9.8.807 (Pro)...
CVE-2019-7411——Multiple stored cross-site scripting (XSS) in the MyThemeShop Launcher plugin 1.0.8 for WordPress allow remote authentic...
CVE-2019-7409——Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbi...
CVE-2019-7404——An issue was discovered on LG GAMP-7100, GAPM-7200, and GAPM-8000 routers. An unauthenticated user can read a log file v...
CVE-2019-12043——In remarkable 1.7.1, lib/parser_inline.js mishandles URL filtering, which allows attackers to trigger XSS via unprintabl...
CVE-2019-11888——Go through 1.12.5 on Windows mishandles process creation with a nil environment in conjunction with a non-nil token, whi...
CVE-2019-11886——The WaspThemes Visual CSS Style Editor (aka yellow-pencil-visual-theme-customizer) plugin before 7.2.1 for WordPress all...
CVE-2019-11885——eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr...
CVE-2019-5437——Information exposure through the directory listing in npm's harp module allows to access files that are supposed to be i...
CVE-2019-5677——NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-5675——NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer ...
CVE-2019-5496——Oncommand Insight versions prior to 7.3.5 shipped without certain HTTP Security headers configured which could allow an ...
CVE-2019-5495——OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security heade...
CVE-2019-11066——openid.php in LightOpenID through 1.3.1 allows SSRF via a crafted OpenID 2.0 assertion request using the HTTP GET method...
CVE-2019-11059——Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
CVE-2019-5494——OnCommand Unified Manager 7-Mode prior to version 5.2.4 shipped without certain HTTP Security headers configured which c...
CVE-2019-11879——The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now