2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-2027In floor0_inverse1 of floor0.c, there is a possible out of bounds write due to an incorrect bounds check. This could lea...
CVE-2019-2026In updateAssistMenuItems of Editor.java, there is a possible escape from the Setup Wizard due to a missing permission ch...
CVE-2019-9841Vesta Control Panel 0.9.8-23 allows XSS via a crafted URL.
CVE-2019-5008hw/sparc64/sun4u.c in QEMU 3.1.50 is vulnerable to a NULL pointer dereference, which allows the attacker to cause a deni...
CVE-2019-11344data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that s...
CVE-2019-10886An incorrect access control exists in the Sony Photo Sharing Plus application in the firmware before PKG6.5629 version (...
CVE-2019-11340util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, i...
CVE-2019-11339The studio profile decoder in libavcodec/mpeg4videodec.c in FFmpeg 4.0 before 4.0.4 and 4.1 before 4.1.2 allows remote a...
CVE-2019-9161WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a Remote Code Execution issue allowing remote...
CVE-2019-11332MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucent...
CVE-2019-9160WAC on the Sangfor Sundray WLAN Controller version 3.7.4.2 and earlier has a backdoor account allowing a remote attacker...
CVE-2019-11331Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fixed port number is not req...
CVE-2019-11015A vulnerability was found in the MIUI OS version 10.1.3.0 that allows a physically proximate attacker to bypass Lockscre...
CVE-2019-11324The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is differ...
CVE-2019-10893CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to...
CVE-2019-11084GAuth 0.9.9 beta has stored XSS that shows a popup repeatedly and discloses cookies.
CVE-2019-9005The Cprime Power Scripts app before 4.0.14 for Atlassian Jira allows Directory Traversal.
CVE-2019-11223An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers...
CVE-2019-8999An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an a...
CVE-2019-11322An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in...
CVE-2019-11321An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests t...
CVE-2019-11320In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrat...
CVE-2019-11319An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware ...
CVE-2019-10304A cross-site request forgery vulnerability in Jenkins XebiaLabs XL Deploy Plugin in the Credential#doValidateUserNamePas...
CVE-2019-10300A cross-site request forgery vulnerability in Jenkins GitLab Plugin 1.5.11 and earlier in the GitLabConnectionConfig#doT...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now