2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-2027 | — | — | 1.2% | Apr 19, 2019 | In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lea... |
| CVE-2019-2026 | — | — | 0.1% | Apr 19, 2019 | In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission ch... |
| CVE-2019-9841 | — | — | 1.3% | Apr 19, 2019 | Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL. |
| CVE-2019-5008 | — | — | 2.8% | Apr 19, 2019 | hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a deni... |
| CVE-2019-11344 | — | — | 3.6% | Apr 19, 2019 | data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that s... |
| CVE-2019-10886 | — | — | 3.0% | Apr 19, 2019 | An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (... |
| CVE-2019-11340 | — | — | 1.9% | Apr 19, 2019 | util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, i... |
| CVE-2019-11339 | — | — | 2.8% | Apr 19, 2019 | The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote a... |
| CVE-2019-9161 | — | — | 4.6% | Apr 18, 2019 | WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote... |
| CVE-2019-11332 | — | — | 1.8% | Apr 18, 2019 | MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucent... |
| CVE-2019-9160 | — | — | 3.2% | Apr 18, 2019 | WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker... |
| CVE-2019-11331 | — | — | 2.6% | Apr 18, 2019 | Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not req... |
| CVE-2019-11015 | — | — | 0.5% | Apr 18, 2019 | A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscre... |
| CVE-2019-11324 | — | — | 2.8% | Apr 18, 2019 | The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is differ... |
| CVE-2019-10893 | — | — | 2.9% | Apr 18, 2019 | CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to... |
| CVE-2019-11084 | — | — | 0.8% | Apr 18, 2019 | GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies. |
| CVE-2019-9005 | — | — | 2.1% | Apr 18, 2019 | The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal. |
| CVE-2019-11223 | — | — | 8.8% | Apr 18, 2019 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers... |
| CVE-2019-8999 | — | — | 1.5% | Apr 18, 2019 | An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an a... |
| CVE-2019-11322 | — | — | 3.9% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in... |
| CVE-2019-11321 | — | — | 1.3% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests t... |
| CVE-2019-11320 | — | — | 1.7% | Apr 18, 2019 | In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrat... |
| CVE-2019-11319 | — | — | 3.9% | Apr 18, 2019 | An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware ... |
| CVE-2019-10304 | — | — | 0.9% | Apr 18, 2019 | A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePas... |
| CVE-2019-10300 | — | — | 1.4% | Apr 18, 2019 | A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doT... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now