2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11618 | — | — | 2.3% | Apr 30, 2019 | doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this vulnerability to gain ... |
| CVE-2019-11617 | — | — | 0.8% | Apr 30, 2019 | doorGets 7.0 has a CSRF vulnerability in /doorgets/app/requests/user/configurationRequest.php. A remote attacker can exp... |
| CVE-2019-11616 | — | — | 2.4% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /setup/temp/admin.php and /setup/temp/database.php.... |
| CVE-2019-11615 | — | — | 1.5% | Apr 30, 2019 | /fileman/php/upload.php in doorGets 7.0 has an arbitrary file upload vulnerability. A remote normal registered user can ... |
| CVE-2019-11614 | — | — | 1.5% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/commentView.php. A remote unauthorized attack... |
| CVE-2019-11613 | — | — | 1.2% | Apr 30, 2019 | doorGets 7.0 has a SQL injection vulnerability in /doorgets/app/views/ajax/contactView.php. A remote normal registered u... |
| CVE-2019-11612 | — | — | 2.7% | Apr 30, 2019 | doorGets 7.0 has an arbitrary file deletion vulnerability in /fileman/php/deletefile.php. A remote unauthenticated attac... |
| CVE-2019-11611 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/download.php. A remote unauthenticated... |
| CVE-2019-11610 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/downloaddir.php. A remote unauthentica... |
| CVE-2019-11609 | — | — | 4.0% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/movefile.php. A remote unauthenticated... |
| CVE-2019-11608 | — | — | 4.1% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/renamefile.php. A remote unauthenticat... |
| CVE-2019-11607 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copydir.php. A remote unauthenticated ... |
| CVE-2019-11606 | — | — | 3.9% | Apr 30, 2019 | doorGets 7.0 has a sensitive information disclosure vulnerability in /fileman/php/copyfile.php. A remote unauthenticated... |
| CVE-2019-9486 | — | — | 2.3% | Apr 30, 2019 | STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the H... |
| CVE-2019-10272 | — | — | 0.7% | Apr 30, 2019 | An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRe... |
| CVE-2019-10948 | — | — | 1.6% | Apr 30, 2019 | Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Ca... |
| CVE-2019-6494 | — | — | 1.1% | Apr 30, 2019 | IMFForceDelete.sys in IObit Malware Fighter 6.2 allows a low privileged user to send IOCTL 0x8016E000 along with a user ... |
| CVE-2019-10317 | — | — | 1.5% | Apr 30, 2019 | Jenkins SiteMonitor Plugin 0.5 and earlier disabled SSL/TLS and hostname verification globally for the Jenkins master JV... |
| CVE-2019-10315 | — | — | 2.1% | Apr 30, 2019 | Jenkins GitHub Authentication Plugin 0.31 and earlier did not use the state parameter of OAuth to prevent CSRF. |
| CVE-2019-10314 | — | — | 1.5% | Apr 30, 2019 | Jenkins Koji Plugin disables SSL/TLS and hostname verification globally for the Jenkins master JVM. |
| CVE-2019-10310 | — | — | 1.5% | Apr 30, 2019 | A cross-site request forgery vulnerability in Jenkins Ansible Tower Plugin 0.9.1 and earlier in the TowerInstallation.To... |
| CVE-2019-10309 | — | — | 1.8% | Apr 30, 2019 | Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not ... |
| CVE-2019-10307 | — | — | 1.0% | Apr 30, 2019 | A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGr... |
| CVE-2019-3892 | — | — | — | Apr 30, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11599. Reason: This candidate is a reservation d... |
| CVE-2019-3562 | — | — | 1.1% | Apr 29, 2019 | A remote web page could inject arbitrary HTML code into the Oculus Browser UI, allowing an attacker to spoof UI and pote... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now