2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-11511Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API.
CVE-2019-11504Zotonic before version 0.47 has mod_admin XSS.
CVE-2019-11503snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the cur...
CVE-2019-11502snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first ca...
CVE-2019-11218Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server...
CVE-2019-11217The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the conte...
CVE-2019-10008Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session...
CVE-2019-9951Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M...
CVE-2019-9950Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M...
CVE-2019-9635NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file.
CVE-2019-10691The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting...
CVE-2019-9928GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a ser...
CVE-2019-9734Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of c...
CVE-2019-7214SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co...
CVE-2019-7213SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary...
CVE-2019-7212SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access othe...
CVE-2019-7211SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by ...
CVE-2019-11081A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative a...
CVE-2019-10239Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un...
CVE-2019-9724aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File w...
CVE-2019-11490An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendq...
CVE-2019-10688VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE...
CVE-2019-7727In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfac...
CVE-2019-10711Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until W...
CVE-2019-10710Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticat...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now