2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9807 | — | — | 0.8% | Apr 26, 2019 | When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal aler... |
| CVE-2019-9806 | — | — | 1.1% | Apr 26, 2019 | A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed a... |
| CVE-2019-9804 | — | — | 1.8% | Apr 26, 2019 | In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on ... |
| CVE-2019-9803 | — | — | 0.6% | Apr 26, 2019 | The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), n... |
| CVE-2019-9802 | — | — | 1.1% | Apr 26, 2019 | If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to rend... |
| CVE-2019-9801 | — | — | 1.3% | Apr 26, 2019 | Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application... |
| CVE-2019-9799 | — | — | 1.1% | Apr 26, 2019 | Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be ... |
| CVE-2019-9798 | — | — | 0.9% | Apr 26, 2019 | On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This ... |
| CVE-2019-9797 | — | — | 1.1% | Apr 26, 2019 | Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitm... |
| CVE-2019-9796 | — | — | 2.0% | Apr 26, 2019 | A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh drive... |
| CVE-2019-9795 | — | — | 1.7% | Apr 26, 2019 | A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious... |
| CVE-2019-9794 | — | — | 1.8% | Apr 26, 2019 | A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocatio... |
| CVE-2019-9793 | — | — | 1.6% | Apr 26, 2019 | A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitig... |
| CVE-2019-9790 | — | — | 1.8% | Apr 26, 2019 | A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and ... |
| CVE-2019-9789 | — | — | 1.2% | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed ev... |
| CVE-2019-0186 | — | — | 20.6% | Apr 26, 2019 | The input fields of the Apache Pluto "Chat Room" demo portlet 3.0.0 and 3.0.1 are vulnerable to Cross-Site Scripting (XS... |
| CVE-2019-11493 | — | — | 1.4% | Apr 26, 2019 | VeryPDF 4.1 has a Memory Overflow leading to Code Execution because pdfocx!CxImageTIF::operator in pdfocx.ocx (used by p... |
| CVE-2019-11489 | — | — | 2.6% | Apr 25, 2019 | Incorrect Access Control in the Administrative Management Interface in SimplyBook.me Enterprise before 2019-04-23 allows... |
| CVE-2019-11488 | — | — | 1.5% | Apr 25, 2019 | Incorrect Access Control in the Account Access / Password Reset Link in SimplyBook.me Enterprise before 2019-04-23 allow... |
| CVE-2019-9669 | — | — | 1.0% | Apr 25, 2019 | The Wordfence plugin 7.2.3 for WordPress allows XSS via a unique attack vector. NOTE: It has been asserted that this is ... |
| CVE-2019-11519 | — | — | 1.2% | Apr 25, 2019 | Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configuration... |
| CVE-2019-11518 | — | — | 1.3% | Apr 25, 2019 | An issue was discovered in SEMCMS 3.8. SEMCMS_Inquiry.php allows AID[] SQL Injection because the class.phpmailer.php inj... |
| CVE-2019-11515 | — | — | 2.1% | Apr 25, 2019 | core/classes/db_backup.php in Gila CMS 1.10.1 allows admin/db_backup?download= absolute path traversal to read arbitrary... |
| CVE-2019-11514 | — | — | 1.3% | Apr 25, 2019 | User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens. |
| CVE-2019-11513 | — | — | 0.6% | Apr 25, 2019 | The File Manager in CMS Made Simple through 2.2.10 has Reflected XSS via the "New name" field in a Rename action. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now