2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-3561Insufficient boundary checks for the strrpos and strripos functions allow access to out-of-bounds memory. This affects a...
CVE-2019-3493A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10....
CVE-2019-11598In ImageMagick 7.0.8-40 Q16, there is a heap-based buffer over-read in the function WritePNMImage of coders/pnm.c, which...
CVE-2019-11597In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi...
CVE-2019-11596In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This cau...
CVE-2019-11595In uBlock before 0.9.5.15, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-s...
CVE-2019-11594In AdBlock before 3.45.0, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a client-si...
CVE-2019-11593In Adblock Plus before 3.5.2, the $rewrite filter option allows filter-list maintainers to run arbitrary code in a clien...
CVE-2019-5492Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthentica...
CVE-2019-11592WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscat...
CVE-2019-11590The 10Web Form Maker plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, wi...
CVE-2019-11577dhcpcd before 7.2.1 contains a buffer overflow in dhcp6_findna in dhcp6.c when reading NA/TA addresses.
CVE-2019-11576Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, t...
CVE-2019-11568An issue was discovered in AikCms v2.0. There is a File upload vulnerability, as demonstrated by an admin/page/system/na...
CVE-2019-11567An issue was discovered in AikCms v2.0. There is a SQL Injection vulnerability via $_GET['del'], as demonstrated by an a...
CVE-2019-11565Server Side Request Forgery (SSRF) exists in the Print My Blog plugin before 1.6.7 for WordPress via the site parameter.
CVE-2019-11555The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate...
CVE-2019-11533Cross-site scripting (XSS) vulnerability in ProjectSend before r1070 allows remote attackers to inject arbitrary web scr...
CVE-2019-11492ProjectSend before r1070 writes user passwords to the server logs.
CVE-2019-6689An issue was discovered in Dillon Kane Tidal Workload Automation Agent 3.2.0.5 (formerly known as Cisco Workload Automat...
CVE-2019-11220An authentication flaw in Shenzhen Yunni Technology iLnkP2P allows remote attackers to actively intercept user-to-device...
CVE-2019-11219The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from...
CVE-2019-9813Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi...
CVE-2019-9809If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert me...
CVE-2019-9808If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now