2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-11451 | — | — | 1.3% | Apr 22, 2019 | whatsns 4.0 allows index.php?inform/add.html qid SQL injection. |
| CVE-2019-11450 | — | — | 1.5% | Apr 22, 2019 | whatsns 4.0 allows index.php?question/ajaxadd.html title SQL injection. |
| CVE-2019-11449 | — | — | 0.9% | Apr 22, 2019 | I, Librarian 4.10 has XSS via the notes.php notes parameter. |
| CVE-2019-11448 | — | — | 12.4% | Apr 22, 2019 | An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain th... |
| CVE-2019-11447 | — | — | 52.9% | Apr 22, 2019 | An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce... |
| CVE-2019-11446 | — | — | 7.9% | Apr 22, 2019 | An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user ... |
| CVE-2019-11445 | — | — | 14.5% | Apr 22, 2019 | OpenKM 6.3.2 through 6.3.7 allows an attacker to upload a malicious JSP file into the /okm:root directories and move tha... |
| CVE-2019-11444 | — | — | 12.8% | Apr 22, 2019 | An issue was discovered in Liferay Portal CE 7.1.2 GA3. An attacker can use Liferay's Groovy script console to execute O... |
| CVE-2019-11428 | — | — | 0.9% | Apr 22, 2019 | I, Librarian 4.10 has XSS via the export.php export_files parameter. |
| CVE-2019-11427 | — | — | 0.8% | Apr 22, 2019 | An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q p... |
| CVE-2019-11426 | — | — | 0.8% | Apr 22, 2019 | An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app... |
| CVE-2019-11418 | — | — | 1.5% | Apr 22, 2019 | apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 inte... |
| CVE-2019-11417 | — | — | 1.5% | Apr 22, 2019 | system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a str... |
| CVE-2019-11416 | — | — | 3.9% | Apr 22, 2019 | A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstr... |
| CVE-2019-11415 | — | — | 13.7% | Apr 22, 2019 | An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause... |
| CVE-2019-11414 | — | — | 1.3% | Apr 22, 2019 | An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain ... |
| CVE-2019-11413 | — | — | 2.3% | Apr 22, 2019 | An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a... |
| CVE-2019-11411 | — | — | 3.3% | Apr 22, 2019 | An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a st... |
| CVE-2019-11401 | — | — | 2.9% | Apr 22, 2019 | A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administ... |
| CVE-2019-11395 | — | — | 14.6% | Apr 22, 2019 | A buffer overflow in MailCarrier 2.51 allows remote attackers to execute arbitrary code via a long string, as demonstrat... |
| CVE-2019-11393 | — | — | 2.1% | Apr 22, 2019 | An issue was discovered in /admin/users/update in M/Monit before 3.7.3. It allows unprivileged users to escalate their p... |
| CVE-2019-11235 | — | — | 3.6% | Apr 22, 2019 | FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that ... |
| CVE-2019-11234 | — | — | 7.6% | Apr 22, 2019 | FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a si... |
| CVE-2019-11371 | — | — | 1.6% | Apr 20, 2019 | BWA (aka Burrow-Wheeler Aligner) 0.7.17 r1198 has a Buffer Overflow via a long prefix that is mishandled in bns_fasta2bn... |
| CVE-2019-11378 | — | — | 3.6% | Apr 20, 2019 | An issue was discovered in ProjectSend r1053. upload-process-form.php allows finished_files[]=../ directory traversal. I... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now