2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-11398Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra...
CVE-2019-2053In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This...
CVE-2019-2052In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote inf...
CVE-2019-2051In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote ...
CVE-2019-2050In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This cou...
CVE-2019-2049In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after fr...
CVE-2019-2047In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote ...
CVE-2019-2046In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. T...
CVE-2019-2045In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote ...
CVE-2019-2044In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bou...
CVE-2019-2043In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay atta...
CVE-2019-11550Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation.
CVE-2019-11819Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/syste...
CVE-2019-11818Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/sys...
CVE-2019-11643Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inje...
CVE-2019-11642A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authent...
CVE-2019-11564A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT...
CVE-2019-11561The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is trigge...
CVE-2019-8387MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
CVE-2019-8349Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script...
CVE-2019-11814An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in tit...
CVE-2019-11813An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS...
CVE-2019-11812A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be inc...
CVE-2019-10712The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750...
CVE-2019-7746JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now