2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9787 | — | — | 43.8% | Mar 14, 2019 | WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated use... |
| CVE-2019-9785 | — | — | 4.2% | Mar 14, 2019 | gitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a javasc... |
| CVE-2019-9769 | — | — | 2.3% | Mar 14, 2019 | PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad... |
| CVE-2019-9768 | — | — | 11.7% | Mar 14, 2019 | Thinkst Canarytokens through commit hash 4e89ee0 (2019-03-01) relies on limited variation in size, metadata, and timesta... |
| CVE-2019-9767 | — | — | 8.0% | Mar 14, 2019 | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ... |
| CVE-2019-9766 | — | — | 8.0% | Mar 14, 2019 | Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to ... |
| CVE-2019-9765 | — | — | 0.9% | Mar 14, 2019 | In Blog_mini 1.0, XSS exists via the author name of a comment reply in the app/main/views.py articleDetails() function, ... |
| CVE-2019-9762 | — | — | 5.1% | Mar 14, 2019 | A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnera... |
| CVE-2019-9761 | — | — | 1.7% | Mar 14, 2019 | An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network... |
| CVE-2019-9760 | — | — | 53.1% | Mar 14, 2019 | FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont... |
| CVE-2019-9754 | — | — | 0.9% | Mar 13, 2019 | An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byt... |
| CVE-2019-9751 | — | — | 0.8% | Mar 13, 2019 | An issue was discovered in Open Ticket Request System (OTRS) 6.x before 6.0.17 and 7.x before 7.0.5. An attacker who is ... |
| CVE-2019-6599 | — | — | 0.8% | Mar 13, 2019 | In BIG-IP 11.6.1-11.6.3.2 or 11.5.1-11.5.8, or Enterprise Manager 3.1.1, improper escaping of values in an undisclosed p... |
| CVE-2019-6598 | — | — | 1.1% | Mar 13, 2019 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1... |
| CVE-2019-6597 | — | — | 1.3% | Mar 13, 2019 | In BIG-IP 13.0.0-13.1.1.1, 12.1.0-12.1.3.7, 11.6.1-11.6.3.2, or 11.5.1-11.5.8 or Enterprise Manager 3.1.1, when authenti... |
| CVE-2019-6596 | — | — | 1.4% | Mar 13, 2019 | In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, 12.1.0-12.1.3.6, 11.6.1-11.6.3.2, or 11.5.1-11.5.8, when processing fragment... |
| CVE-2019-9750 | — | — | 1.3% | Mar 13, 2019 | In IoTivity through 1.3.1, the CoAP server interface can be used for Distributed Denial of Service attacks using source ... |
| CVE-2019-9748 | — | — | 2.4% | Mar 13, 2019 | In tinysvcmdns through 2018-01-16, an mDNS server processing a crafted packet can perform arbitrary data read operations... |
| CVE-2019-9747 | — | — | 1.4% | Mar 13, 2019 | In tinysvcmdns through 2018-01-16, a maliciously crafted mDNS (Multicast DNS) packet triggers an infinite loop while par... |
| CVE-2019-9746 | — | — | 1.6% | Mar 13, 2019 | In libwebm before 2019-03-08, a NULL pointer dereference caused by the functions OutputCluster and OutputTracks in webm_... |
| CVE-2019-9742 | — | — | 1.4% | Mar 13, 2019 | gdwfpcd.sys in G Data Total Security before 2019-02-22 allows an attacker to bypass ACLs because Interpreted Device Char... |
| CVE-2019-9738 | — | — | 0.9% | Mar 13, 2019 | jimmykuu Gopher 2.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. |
| CVE-2019-9736 | — | — | 0.8% | Mar 13, 2019 | DOM-based XSS exists in 1024Tools Markdown 1.0 via vectors involving the '<EMBED SRC="data:image/svg+xml' substring. |
| CVE-2019-9735 | — | — | 3.7% | Mar 13, 2019 | An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x bef... |
| CVE-2019-9729 | — | — | 1.0% | Mar 12, 2019 | In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now