2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11678 | — | — | 9.5% | May 2, 2019 | The "default reports" feature in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123218 is vulnerable to SQL Injec... |
| CVE-2019-11677 | — | — | 9.4% | May 2, 2019 | The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML E... |
| CVE-2019-11676 | — | — | 1.9% | May 2, 2019 | The user defined DNS name in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to stored XSS at... |
| CVE-2019-11675 | — | — | 0.2% | May 2, 2019 | The groonga-httpd package 6.1.5-1 for Debian sets the /var/log/groonga ownership to the groonga account, which might let... |
| CVE-2019-11641 | — | — | 1.3% | May 1, 2019 | Anomali Agave (formerly Drupot) through 1.0.0 fails to avoid fingerprinting by including predictable data and minimal va... |
| CVE-2019-11640 | — | — | 1.9% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_sim... |
| CVE-2019-11639 | — | — | 1.9% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum ... |
| CVE-2019-11638 | — | — | 1.4% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p ... |
| CVE-2019-11637 | — | — | 1.4% | May 1, 2019 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at r... |
| CVE-2019-3791 | — | — | — | May 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-11636 | — | — | 2.2% | May 1, 2019 | Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from... |
| CVE-2019-11633 | — | — | 1.4% | May 1, 2019 | HoneyPress through 2016-09-27 can be fingerprinted by attackers because of the ingrained unique www.atxsec.com and ayylm... |
| CVE-2019-11632 | — | — | 1.2% | May 1, 2019 | In Octopus Deploy 2019.1.0 through 2019.3.1 and 2019.4.0 through 2019.4.5, an authenticated user with the VariableViewUn... |
| CVE-2019-11631 | — | — | — | May 1, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-0214 | — | — | 4.9% | Apr 30, 2019 | In Apache Archiva 2.0.0 - 2.2.3, it is possible to write files to the archiva server at arbitrary locations by using the... |
| CVE-2019-0213 | — | — | 4.9% | Apr 30, 2019 | In Apache Archiva before 2.2.4, it may be possible to store malicious XSS code into central configuration entries, i.e. ... |
| CVE-2019-0194 | — | — | 8.5% | Apr 30, 2019 | Apache Camel's File is vulnerable to directory traversal. Camel 2.21.0 to 2.21.3, 2.22.0 to 2.22.2, 2.23.0 and the unsup... |
| CVE-2019-11626 | — | — | 1.3% | Apr 30, 2019 | routers/ajaxRouter.php in doorGets 7.0 has a web site physical path leakage vulnerability, as demonstrated by an ajax/in... |
| CVE-2019-11625 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/emailingRequest.php. A remote background a... |
| CVE-2019-11624 | — | — | 1.6% | Apr 30, 2019 | doorGets 7.0 has an arbitrary file deletion vulnerability in /doorgets/app/requests/user/configurationRequest.php. A rem... |
| CVE-2019-11623 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=sitew... |
| CVE-2019-11622 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote backgr... |
| CVE-2019-11621 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=netwo... |
| CVE-2019-11620 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/modulecategoryRequest.php. A remote backgr... |
| CVE-2019-11619 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/requests/user/configurationRequest.php when action=analy... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now