2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11398 | — | — | 3.5% | May 8, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra... |
| CVE-2019-2053 | — | — | 0.2% | May 8, 2019 | In wnm_parse_neighbor_report_elem of wnm_sta.c, there is a possible out-of-bounds read due to missing bounds check. This... |
| CVE-2019-2052 | — | — | 1.0% | May 8, 2019 | In VisitPointers of heap.cc, there is a possible out-of-bounds read due to type confusion. This could lead to remote inf... |
| CVE-2019-2051 | — | — | 1.0% | May 8, 2019 | In heap of spaces.h, there is a possible out of bounds read due to improper input validation. This could lead to remote ... |
| CVE-2019-2050 | — | — | 0.1% | May 8, 2019 | In tearDownClientInterface of WificondControl.java, there is a possible use after free due to improper locking. This cou... |
| CVE-2019-2049 | — | — | 0.2% | May 8, 2019 | In SendMediaUpdate and SendFolderUpdate of avrcp_service.cc, there is a possible memory corruption due to a use after fr... |
| CVE-2019-2047 | — | — | 1.4% | May 8, 2019 | In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote ... |
| CVE-2019-2046 | — | — | 1.3% | May 8, 2019 | In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. T... |
| CVE-2019-2045 | — | — | 1.4% | May 8, 2019 | In JSCallTyper of typer.cc, there is an out of bounds write due to an incorrect bounds check. This could lead to remote ... |
| CVE-2019-2044 | — | — | 1.2% | May 8, 2019 | In MakeMP>G4VideoCodecSpecificData of APacketSource.cpp, there is a possible out-of-bounds write due to an incorrect bou... |
| CVE-2019-2043 | — | — | 0.2% | May 8, 2019 | In SmsDefaultDialog.onStart of SmsDefaultDialog.java, there is a possible escalation of privilege due to an overlay atta... |
| CVE-2019-11550 | — | — | 0.6% | May 8, 2019 | Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. |
| CVE-2019-11819 | — | — | 1.0% | May 8, 2019 | Alkacon OpenCMS v10.5.4 and before is affected by CSV (aka Excel Macro) Injection in the module New User (/opencms/syste... |
| CVE-2019-11818 | — | — | 0.8% | May 8, 2019 | Alkacon OpenCMS v10.5.4 and before is affected by stored cross site scripting (XSS) in the module New User (/opencms/sys... |
| CVE-2019-11643 | — | — | 0.9% | May 8, 2019 | Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inje... |
| CVE-2019-11642 | — | — | 1.5% | May 8, 2019 | A log poisoning vulnerability has been discovered in the OneShield Policy (Dragon Core) framework before 5.1.10. Authent... |
| CVE-2019-11564 | — | — | 2.6% | May 8, 2019 | A cross-site scripting (XSS) vulnerability in HumHub 1.3.12 allows remote attackers to inject arbitrary web script or HT... |
| CVE-2019-11561 | — | — | 1.0% | May 8, 2019 | The Chuango 433 MHz burglar-alarm product line is vulnerable to a Denial of Service attack. When the condition is trigge... |
| CVE-2019-8387 | — | — | 55.7% | May 8, 2019 | MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component. |
| CVE-2019-8349 | — | — | 2.2% | May 8, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in HTMLy 2.7.4 allow remote attackers to inject arbitrary web script... |
| CVE-2019-11814 | — | — | 0.8% | May 8, 2019 | An issue was discovered in app/webroot/js/misp.js in MISP before 2.4.107. There is persistent XSS via image names in tit... |
| CVE-2019-11813 | — | — | 0.8% | May 8, 2019 | An issue was discovered in app/View/Elements/Events/View/value_field.ctp in MISP before 2.4.107. There is persistent XSS... |
| CVE-2019-11812 | — | — | 0.8% | May 8, 2019 | A persistent XSS issue was discovered in app/View/Helper/CommandHelper.php in MISP before 2.4.107. JavaScript can be inc... |
| CVE-2019-10712 | — | — | 2.8% | May 7, 2019 | The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750... |
| CVE-2019-7746 | — | — | 1.1% | May 7, 2019 | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain an admin token by making a /cgi-bin/qcmap_... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now