2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9938 | — | — | 0.9% | Mar 22, 2019 | The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open"... |
| CVE-2019-9937 | — | — | 6.3% | Mar 22, 2019 | In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL P... |
| CVE-2019-9936 | — | — | 5.7% | Mar 22, 2019 | In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5Ha... |
| CVE-2019-9927 | — | — | 3.6% | Mar 22, 2019 | Caret before 2019-02-22 allows Remote Code Execution. |
| CVE-2019-9925 | — | — | 0.8% | Mar 22, 2019 | S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter. |
| CVE-2019-9915 | — | — | 3.6% | Mar 22, 2019 | GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter. |
| CVE-2019-9914 | — | — | 1.7% | Mar 22, 2019 | The yop-poll plugin before 6.0.3 for WordPress has wp-admin/admin.php?page=yop-polls&action=view-votes poll_id XSS. |
| CVE-2019-9913 | — | — | 1.4% | Mar 22, 2019 | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term X... |
| CVE-2019-9910 | — | — | 1.4% | Mar 22, 2019 | The kingcomposer plugin 2.7.6 for WordPress has wp-admin/admin.php?page=kc-mapper id XSS. |
| CVE-2019-9909 | — | — | 1.4% | Mar 22, 2019 | The "Donation Plugin and Fundraising Platform" plugin before 2.3.1 for WordPress has wp-admin/edit.php csv XSS. |
| CVE-2019-9908 | — | — | 1.4% | Mar 22, 2019 | The font-organizer plugin 2.1.1 for WordPress has wp-admin/options-general.php manage_font_id XSS. |
| CVE-2019-8351 | — | — | 1.3% | Mar 21, 2019 | Heimdal Thor Agent 2.5.17x before 2.5.173 does not verify X.509 certificates from TLS servers, which allows remote attac... |
| CVE-2019-7539 | — | — | 1.6% | Mar 21, 2019 | A code injection issue was discovered in ipycache through 2016-05-31. |
| CVE-2019-7537 | — | — | 3.4% | Mar 21, 2019 | An issue was discovered in Donfig 0.3.0. There is a vulnerability in the collect_yaml method in config_obj.py. It can ex... |
| CVE-2019-5490 | — | — | 3.5% | Mar 21, 2019 | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a def... |
| CVE-2019-8997 | — | — | 2.3% | Mar 21, 2019 | An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions ear... |
| CVE-2019-0198 | — | — | — | Mar 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca... |
| CVE-2019-6491 | — | — | 1.3% | Mar 21, 2019 | RISI Gestao de Horarios v3201.09.08 rev.23 allows SQL Injection. |
| CVE-2019-9898 | — | — | 3.9% | Mar 21, 2019 | Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71. |
| CVE-2019-9897 | — | — | 3.0% | Mar 21, 2019 | Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71. |
| CVE-2019-9895 | — | — | 2.6% | Mar 21, 2019 | In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client for... |
| CVE-2019-9894 | — | — | 2.4% | Mar 21, 2019 | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification. |
| CVE-2019-9893 | — | — | 3.0% | Mar 21, 2019 | libseccomp before 2.4.0 did not correctly generate 64-bit syscall argument comparisons using the arithmetic operators (L... |
| CVE-2019-9889 | — | — | 2.4% | Mar 21, 2019 | In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results i... |
| CVE-2019-9878 | — | — | 1.2% | Mar 21, 2019 | There is an invalid memory access in the function GfxIndexedColorSpace::mapColorToBase() located in GfxState.cc in Xpdf ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now