2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11511 | — | — | 2.1% | Apr 25, 2019 | Zoho ManageEngine ADSelfService Plus before build 5708 has XSS via the mobile app API. |
| CVE-2019-11504 | — | — | 2.5% | Apr 24, 2019 | Zotonic before version 0.47 has mod_admin XSS. |
| CVE-2019-11503 | — | — | 2.4% | Apr 24, 2019 | snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the cur... |
| CVE-2019-11502 | — | — | 2.5% | Apr 24, 2019 | snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first ca... |
| CVE-2019-11218 | — | — | 1.2% | Apr 24, 2019 | Improper handling of extra parameters in the AccountController (User Profile edit) in Jakub Chodounsky Bonobo Git Server... |
| CVE-2019-11217 | — | — | 3.8% | Apr 24, 2019 | The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the conte... |
| CVE-2019-10008 | — | — | 19.7% | Apr 24, 2019 | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session... |
| CVE-2019-9951 | — | — | 1.7% | Apr 24, 2019 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M... |
| CVE-2019-9950 | — | — | 2.3% | Apr 24, 2019 | Western Digital My Cloud, My Cloud Mirror Gen2, My Cloud EX2 Ultra, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100, M... |
| CVE-2019-9635 | — | — | 0.5% | Apr 24, 2019 | NULL pointer dereference in Google TensorFlow before 1.12.2 could cause a denial of service via an invalid GIF file. |
| CVE-2019-10691 | — | — | 2.8% | Apr 24, 2019 | The JSON encoder in Dovecot before 2.3.5.2 allows attackers to repeatedly crash the authentication service by attempting... |
| CVE-2019-9928 | — | — | 6.0% | Apr 24, 2019 | GStreamer before 1.16.0 has a heap-based buffer overflow in the RTSP connection parser via a crafted response from a ser... |
| CVE-2019-9734 | — | — | 1.6% | Apr 24, 2019 | Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of c... |
| CVE-2019-7214 | — | — | 83.3% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co... |
| CVE-2019-7213 | — | — | 42.1% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 allows directory traversal. An authenticated user could delete arbitrary... |
| CVE-2019-7212 | — | — | 1.0% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6985 has hardcoded secret keys. An unauthenticated attacker could access othe... |
| CVE-2019-7211 | — | — | 0.7% | Apr 24, 2019 | SmarterTools SmarterMail 16.x before build 6995 has stored XSS. JavaScript code could be executed on the application by ... |
| CVE-2019-11081 | — | — | 1.8% | Apr 24, 2019 | A default username and password in Dentsply Sirona Sidexis 4.3.1 and earlier allows an attacker to gain administrative a... |
| CVE-2019-10239 | — | — | 0.4% | Apr 24, 2019 | Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un... |
| CVE-2019-9724 | — | — | 1.4% | Apr 24, 2019 | aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File w... |
| CVE-2019-11490 | — | — | 0.7% | Apr 24, 2019 | An issue was discovered in Npcap 0.992. Sending a malformed .pcap file with the loopback adapter using either pcap_sendq... |
| CVE-2019-10688 | — | — | 0.3% | Apr 23, 2019 | VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE... |
| CVE-2019-7727 | — | — | 3.8% | Apr 23, 2019 | In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfac... |
| CVE-2019-10711 | — | — | 1.4% | Apr 23, 2019 | Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until W... |
| CVE-2019-10710 | — | — | 1.1% | Apr 23, 2019 | Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticat... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now