2019 CVE Vulnerabilities

17,624 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7687——cgi-bin/qcmap_web_cgi on JioFi 4 jmr1140 Amtel_JMR1140_R12.07 devices has POST based reflected XSS via the Page paramete...
CVE-2019-7564——An issue was discovered on Shenzhen Coship WM3300 WiFi Router 5.0.0.55 devices. The password reset functionality of the ...
CVE-2019-7541——Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
CVE-2019-7443——KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBu...
CVE-2019-7427——XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo...
CVE-2019-7426——XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdo...
CVE-2019-10742——Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to acce...
CVE-2019-11629——Sonatype Nexus Repository Manager 2.x before 2.14.13 allows XSS.
CVE-2019-9708——An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administr...
CVE-2019-11560——A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated...
CVE-2019-9709——An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection t...
CVE-2019-11808——Ratpack versions before 1.6.1 generate a session ID using a cryptographically weak PRNG in the JDK's ThreadLocalRandom. ...
CVE-2019-11569——Veeam ONE Reporter 9.5.0.3201 allows CSRF.
CVE-2019-10999——The D-Link DCS series of Wi-Fi cameras contains a stack-based buffer overflow in alphapd, the camera's web server. The o...
CVE-2019-11807——The WooCommerce Checkout Manager plugin before 4.3 for WordPress allows media deletion via the wp-admin/admin-ajax.php?a...
CVE-2019-5434——An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal...
CVE-2019-5433——A user having access to the UI of a Revive Adserver instance could be tricked into clicking on a specifically crafted ad...
CVE-2019-5430——In UniFi Video 3.10.0 and prior, due to the lack of CSRF protection, it is possible to abuse the Web API to make changes...
CVE-2019-11767——Server side request forgery (SSRF) in phpBB before 3.2.6 allows checking for the existence of files and services on the ...
CVE-2019-6618——On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource A...
CVE-2019-11690——gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to deter...
CVE-2019-9826——The fulltext search component in phpBB before 3.2.6 allows Denial of Service.
CVE-2019-3490——A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a...
CVE-2019-11682——A buffer overflow in the SMTP response service in MailCarrier 2.51 allows the attacker to execute arbitrary code remotel...
CVE-2019-11678——The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injec...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now