2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1003042 | — | — | 1.4% | Mar 28, 2019 | A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to contr... |
| CVE-2019-7251 | — | — | 3.8% | Mar 28, 2019 | An Integer Signedness issue (for a return code) in the res_pjsip_sdp_rtp module in Digium Asterisk versions 15.7.1 and e... |
| CVE-2019-10260 | — | — | 0.9% | Mar 28, 2019 | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (colum... |
| CVE-2019-10255 | — | — | 1.7% | Mar 28, 2019 | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in ... |
| CVE-2019-5027 | — | — | — | Mar 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-5028 | — | — | — | Mar 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-5026 | — | — | — | Mar 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-9864 | — | — | 1.0% | Mar 28, 2019 | PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount. |
| CVE-2019-5674 | — | — | 1.2% | Mar 28, 2019 | NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacke... |
| CVE-2019-10254 | — | — | 0.9% | Mar 28, 2019 | In MISP before 2.4.105, the app/View/Layouts/default.ctp default layout template has a Reflected XSS vulnerability. |
| CVE-2019-10251 | — | — | 0.8% | Mar 28, 2019 | The UCWeb UC Browser application through 2019-03-26 for Android uses HTTP to download certain modules associated with PD... |
| CVE-2019-5025 | — | — | — | Mar 28, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2019-10250 | — | — | 0.7% | Mar 28, 2019 | UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downloading certain PDF modules, which allows MITM attacks. |
| CVE-2019-0161 | — | — | 0.4% | Mar 27, 2019 | Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local ac... |
| CVE-2019-10238 | — | — | 0.8% | Mar 27, 2019 | Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter. |
| CVE-2019-10237 | — | — | 0.6% | Mar 27, 2019 | S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&l... |
| CVE-2019-10232 | — | — | 23.2% | Mar 27, 2019 | Teclib GLPI through 9.3.3 has SQL injection via the "cycle" parameter in /scripts/unlock_tasks.php. |
| CVE-2019-10231 | — | — | 2.1% | Mar 27, 2019 | Teclib GLPI before 9.4.1.1 is affected by a PHP type juggling vulnerability allowing bypass of authentication. This occu... |
| CVE-2019-6536 | — | — | 1.2% | Mar 27, 2019 | Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocate... |
| CVE-2019-9860 | — | — | 0.8% | Mar 27, 2019 | Due to unencrypted signal communication and predictability of rolling codes, an attacker can "desynchronize" an ABUS Sec... |
| CVE-2019-9863 | — | — | 2.1% | Mar 27, 2019 | Due to the use of an insecure algorithm for rolling codes in the ABUS Secvest wireless alarm system FUAA50000 3.01.01 an... |
| CVE-2019-9862 | — | — | 0.6% | Mar 27, 2019 | An issue was discovered on ABUS Secvest wireless alarm system FUAA50000 3.01.01 in conjunction with Secvest remote contr... |
| CVE-2019-5927 | — | — | 3.0% | Mar 27, 2019 | Directory traversal vulnerability in 'an' App for iOS Version 3.2.0 and earlier allows remote attackers to read arbitrar... |
| CVE-2019-5926 | — | — | 1.5% | Mar 27, 2019 | Cross-site scripting vulnerability in KinagaCMS versions prior to 6.5 allows remote authenticated attackers to inject ar... |
| CVE-2019-9917 | — | — | 3.1% | Mar 27, 2019 | ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now