2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7745 | — | — | 3.8% | May 7, 2019 | JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices allow remote attackers to obtain the Wi-Fi password by making a cgi-bin/qcm... |
| CVE-2019-7687 | — | — | 1.6% | May 7, 2019 | cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page paramete... |
| CVE-2019-7564 | — | — | 3.0% | May 7, 2019 | An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the ... |
| CVE-2019-7541 | — | — | 3.2% | May 7, 2019 | Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring. |
| CVE-2019-7443 | — | — | 2.4% | May 7, 2019 | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBu... |
| CVE-2019-7427 | — | — | 2.8% | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo... |
| CVE-2019-7426 | — | — | 2.8% | May 7, 2019 | XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo... |
| CVE-2019-10742 | — | — | 6.0% | May 7, 2019 | Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to acce... |
| CVE-2019-11629 | — | — | 0.7% | May 7, 2019 | Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS. |
| CVE-2019-9708 | — | — | 1.0% | May 7, 2019 | An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administr... |
| CVE-2019-11560 | — | — | 1.9% | May 7, 2019 | A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated... |
| CVE-2019-9709 | — | — | 0.6% | May 7, 2019 | An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection t... |
| CVE-2019-11808 | — | — | 1.3% | May 7, 2019 | Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. ... |
| CVE-2019-11569 | — | — | 2.3% | May 6, 2019 | Veeam ONE Reporter 9.5.0.3201 allows CSRF. |
| CVE-2019-10999 | — | — | 3.7% | May 6, 2019 | The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The o... |
| CVE-2019-11807 | — | — | 1.5% | May 6, 2019 | The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a... |
| CVE-2019-5434 | — | — | 57.0% | May 6, 2019 | An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal... |
| CVE-2019-5433 | — | — | 1.7% | May 6, 2019 | A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted ad... |
| CVE-2019-5430 | — | — | 0.7% | May 6, 2019 | In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes... |
| CVE-2019-11767 | — | — | 1.2% | May 5, 2019 | Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the ... |
| CVE-2019-6618 | — | — | 0.9% | May 3, 2019 | On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource A... |
| CVE-2019-11690 | — | — | 1.2% | May 3, 2019 | gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to deter... |
| CVE-2019-9826 | — | — | 2.3% | May 2, 2019 | The fulltext search component in phpBB before 3.2.6 allows Denial of Service. |
| CVE-2019-3490 | — | — | 1.0% | May 2, 2019 | A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a... |
| CVE-2019-11682 | — | — | 3.2% | May 2, 2019 | A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotel... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now