2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-9938The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open"...
CVE-2019-9937In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL P...
CVE-2019-9936In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5Ha...
CVE-2019-9927Caret before 2019-02-22 allows Remote Code Execution.
CVE-2019-9925S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.
CVE-2019-9915GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
CVE-2019-9914The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS.
CVE-2019-9913The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X...
CVE-2019-9910The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS.
CVE-2019-9909The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS.
CVE-2019-9908The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS.
CVE-2019-8351Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attac...
CVE-2019-7539A code injection issue was discovered in ipycache through 2016-05-31.
CVE-2019-7537An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can ex...
CVE-2019-5490Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a def...
CVE-2019-8997An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions ear...
CVE-2019-0198Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2019-6491RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection.
CVE-2019-9898Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
CVE-2019-9897Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
CVE-2019-9895In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client for...
CVE-2019-9894A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
CVE-2019-9893libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (L...
CVE-2019-9889In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results i...
CVE-2019-9878There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now