2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-10654 | — | — | 1.2% | Mar 30, 2019 | The lzo1x_decompress function in liblzo2.so.2 in LZO 2.10, as used in Long Range Zip (aka lrzip) 0.631, allows remote at... |
| CVE-2019-10652 | — | — | 7.1% | Mar 30, 2019 | An issue was discovered in flatCore 1.4.7. acp/acp.php allows remote authenticated administrators to upload arbitrary .p... |
| CVE-2019-10650 | — | — | 4.1% | Mar 30, 2019 | In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, whi... |
| CVE-2019-10648 | — | — | 2.2% | Mar 30, 2019 | Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query... |
| CVE-2019-10647 | — | — | 6.6% | Mar 30, 2019 | ZZZCMS zzzphp v1.6.3 allows remote attackers to execute arbitrary PHP code via a .php URL in the plugins/ueditor/php/con... |
| CVE-2019-10646 | — | — | 0.9% | Mar 30, 2019 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allow... |
| CVE-2019-10644 | — | — | 0.7% | Mar 30, 2019 | An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account. |
| CVE-2019-9695 | — | — | 0.6% | Mar 29, 2019 | Norton Core prior to v278 may be susceptible to an arbitrary code execution issue, which is a type of vulnerability that... |
| CVE-2019-9605 | — | — | 0.6% | Mar 29, 2019 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Reflected Cross-site Scripting (XSS) via the err value in... |
| CVE-2019-9604 | — | — | 0.6% | Mar 29, 2019 | PHP Scripts Mall Online Lottery PHP Readymade Script 1.7.0 has Cross-Site Request Forgery (CSRF) for Edit Profile action... |
| CVE-2019-6481 | — | — | 2.1% | Mar 29, 2019 | Abine Blur 7.8.2431 allows remote attackers to conduct "Second-Factor Auth Bypass" attacks by using the "Perform a right... |
| CVE-2019-10477 | — | — | 1.8% | Mar 29, 2019 | The FusionInventory plugin before 1.4 for GLPI 9.3.x and before 1.1 for GLPI 9.4.x mishandles sendXML actions. |
| CVE-2019-10276 | — | — | 1.8% | Mar 29, 2019 | Western Bridge Cobub Razor 0.8.0 has a file upload vulnerability via the web/assets/swf/uploadify.php URI, as demonstrat... |
| CVE-2019-10262 | — | — | 1.5% | Mar 28, 2019 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in ... |
| CVE-2019-0212 | — | — | 3.9% | Mar 28, 2019 | In all previously released Apache HBase 2.x versions (2.0.0-2.0.4, 2.1.0-2.1.3), authorization was incorrectly applied t... |
| CVE-2019-6608 | — | — | 1.0% | Mar 28, 2019 | On BIG-IP 11.5.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, the snmpd daemon... |
| CVE-2019-6607 | — | — | 0.7% | Mar 28, 2019 | On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross... |
| CVE-2019-6606 | — | — | 1.3% | Mar 28, 2019 | On BIG-IP 11.5.1-11.6.3.4, 12.1.0-12.1.3.7, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, when processing certain SNMP requests ... |
| CVE-2019-6605 | — | — | 1.7% | Mar 28, 2019 | On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, and 12.0.x, an undisclosed sequence of packets received by an SSL virtual server... |
| CVE-2019-6604 | — | — | 1.0% | Mar 28, 2019 | On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions,... |
| CVE-2019-6603 | — | — | 1.8% | Mar 28, 2019 | In BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, and 13.0.0-13.0.1, malformed TCP packets sent to a self IP addres... |
| CVE-2019-6602 | — | — | 1.8% | Mar 28, 2019 | In BIG-IP 11.5.1-11.5.8 and 11.6.1-11.6.3, the Configuration Utility login page may not follow best security practices w... |
| CVE-2019-0224 | — | — | 5.1% | Mar 28, 2019 | In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No inf... |
| CVE-2019-1003046 | — | — | 1.3% | Mar 28, 2019 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attack... |
| CVE-2019-1003044 | — | — | 1.1% | Mar 28, 2019 | A cross-site request forgery vulnerability in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers to con... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now