2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10261 | — | — | 2.4% | Apr 3, 2019 | CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel... |
| CVE-2019-10673 | — | — | 1.8% | Apr 3, 2019 | A CSRF vulnerability in a logged-in user's profile edit form in the Ultimate Member plugin before 2.0.40 for WordPress a... |
| CVE-2019-6506 | — | — | 1.7% | Apr 2, 2019 | SuiteCRM before 7.8.28, 7.9.x and 7.10.x before 7.10.15, and 7.11.x before 7.11.3 allows SQL Injection. |
| CVE-2019-10708 | — | — | 2.6% | Apr 2, 2019 | S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter. |
| CVE-2019-10707 | — | — | 1.5% | Apr 2, 2019 | MKCMS V5.0 has SQL injection via the bplay.php play parameter. |
| CVE-2019-9946 | — | — | 3.1% | Apr 2, 2019 | Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network firewall misconfigurat... |
| CVE-2019-7477 | — | — | 1.2% | Apr 2, 2019 | A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext da... |
| CVE-2019-5524 | — | — | 4.1% | Apr 2, 2019 | VMware Workstation (14.x before 14.1.6) and Fusion (10.x before 10.1.6) contain an out-of-bounds write vulnerability in ... |
| CVE-2019-5515 | — | — | 4.2% | Apr 2, 2019 | VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) and Fusion (11.x before 11.0.3, 10.x before 10.1.6) updates ... |
| CVE-2019-1010260 | — | — | 1.5% | Apr 2, 2019 | Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be co... |
| CVE-2019-9759 | — | — | 1.5% | Apr 2, 2019 | An issue was discovered in TONGDA Office Anywhere 10.18.190121. There is a SQL Injection vulnerability via the general/a... |
| CVE-2019-9193 | — | — | 91.9% | Apr 1, 2019 | In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve... |
| CVE-2019-5519 | — | — | 1.0% | Apr 1, 2019 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.... |
| CVE-2019-5518 | — | — | 0.8% | Apr 1, 2019 | VMware ESXi (6.7 before ESXi670-201903001, 6.5 before ESXi650-201903001, 6.0 before ESXi600-201903001), Workstation (15.... |
| CVE-2019-5514 | — | — | 3.5% | Apr 1, 2019 | VMware VMware Fusion (11.x before 11.0.3) contains a security vulnerability due to certain unauthenticated APIs accessib... |
| CVE-2019-3489 | — | — | 1.7% | Apr 1, 2019 | An unauthenticated file upload vulnerability has been identified in the Web Client component of Micro Focus Content Mana... |
| CVE-2019-5523 | — | — | 3.3% | Apr 1, 2019 | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerabilit... |
| CVE-2019-9132 | — | — | 2.3% | Apr 1, 2019 | Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the mess... |
| CVE-2019-10686 | — | — | 1.6% | Apr 1, 2019 | An SSRF vulnerability was found in an API from Ctrip Apollo through 1.4.0-SNAPSHOT. An attacker may use it to do an intr... |
| CVE-2019-10684 | — | — | 2.4% | Apr 1, 2019 | Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP... |
| CVE-2019-10678 | — | — | 17.3% | Mar 31, 2019 | Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options. |
| CVE-2019-10675 | — | — | — | Mar 31, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-10672 | — | — | 2.4% | Mar 31, 2019 | treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions. |
| CVE-2019-10664 | — | — | 7.5% | Mar 31, 2019 | Domoticz before 4.10578 allows SQL Injection via the idx parameter in CWebServer::GetFloorplanImage in WebServer.cpp. |
| CVE-2019-10663 | — | — | 28.1% | Mar 30, 2019 | Grandstream UCM6204 before 1.0.19.20 devices allow remote authenticated users to conduct SQL injection attacks via the s... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now