2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-11879The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a...
CVE-2019-11082core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Travers...
CVE-2019-11878An issue was discovered on XiongMai Besder IP20H1 V4.02.R12.00035520.12012.047500.00200 cameras. An attacker on the same...
CVE-2019-11871The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
CVE-2019-11870Serendipity before 2.1.5 has XSS via EXIF data that is mishandled in the templates/2k11/admin/media_choose.tpl Editor Pr...
CVE-2019-11869The Yuzo Related Posts plugin 5.12.94 for WordPress has XSS because it mistakenly expects that is_admin() verifies that ...
CVE-2019-7652TheHive Project UnshortenLink analyzer before 1.1, included in Cortex-Analyzers before 1.15.2, has SSRF. To exploit the ...
CVE-2019-11563Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2019-1568Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated atta...
CVE-2019-11842An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandle...
CVE-2019-7181Buffer Overflow vulnerability in myQNAPcloud Connect 1.3.3.0925 and earlier could allow remote attackers to crash the pr...
CVE-2019-9847A vulnerability in LibreOffice hyperlink processing allows an attacker to construct documents containing hyperlinks poin...
CVE-2019-11839njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.push after a resize, related to nj...
CVE-2019-11838njs through 0.3.1, used in NGINX, has a heap-based buffer overflow in Array.prototype.splice after a resize, related to ...
CVE-2019-11837njs through 0.3.1, used in NGINX, has a segmentation fault in String.prototype.toBytes for negative arguments, related t...
CVE-2019-11353The EnGenius EWS660AP router with firmware 2.0.284 allows an attacker to execute arbitrary commands using the built-in p...
CVE-2019-0226Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directo...
CVE-2019-11836The Rediffmail (aka com.rediff.mail.and) application 2.2.6 for Android has cleartext mail content in file storage, persi...
CVE-2019-11832TYPO3 8.x before 8.7.25 and 9.x before 9.5.6 allows remote code execution because it does not properly configure the app...
CVE-2019-11830PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1...
CVE-2019-7442An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault...
CVE-2019-9698Symantec AV Engine, prior to 13.0.9r17, may be susceptible to an arbitrary file deletion issue, which is a type of vulne...
CVE-2019-8285Kaspersky Lab Antivirus Engine version before 04.apr.2019 has a heap-based buffer overflow vulnerability that potentiall...
CVE-2019-11458An issue was discovered in SmtpTransport in CakePHP 3.7.6. An unserialized object with modified internal properties can ...
CVE-2019-11406Subrion CMS 4.2.1 allows _core/en/contacts/ XSS via the name, email, or phone parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now