2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-5925Cross-site scripting vulnerability in Dradis Community Edition Dradis Community Edition v3.11 and earlier and Dradis Pro...
CVE-2019-5923Directory traversal vulnerability in iChain Insurance Wallet App for iOS Version 1.3.0 and earlier allows remote attacke...
CVE-2019-5922Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Troj...
CVE-2019-5921Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unsp...
CVE-2019-5920Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the aut...
CVE-2019-5919An incomplete cryptography of the data store function by using hidden tag in Nablarch 5 (5, and 5u1 to 5u13) allows remo...
CVE-2019-5918Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vec...
CVE-2019-5917azure-umqtt-c (available through GitHub prior to 2017 October 6) allows remote attackers to cause a denial of service vi...
CVE-2019-0277SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from...
CVE-2019-0276Banking services from SAP 9.0 (FSAPPL version 5) and SAP S/4HANA Financial Products Subledger (S4FPSL, version 1) perfor...
CVE-2019-0274SAP Mobile Platform SDK allows an attacker to prevent legitimate users from accessing a service, either by crashing or f...
CVE-2019-0270ABAP Server of SAP NetWeaver and ABAP Platform fail to perform necessary authorization checks for an authenticated user,...
CVE-2019-0269SAP BusinessObjects Business Intelligence Platform (BI Workspace), versions 4.10 and 4.20, does not sufficiently encode ...
CVE-2019-0268SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30, does not sufficiently val...
CVE-2019-9725The Web manager (aka Commander) on Korenix JetPort 5601 and 5601f devices has Persistent XSS via the Port Alias field un...
CVE-2019-9558Mailtraq WebMail version 2.17.7.3550 has Persistent Cross Site Scripting (XSS) via the body of an e-mail message. To exp...
CVE-2019-9557Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerabili...
CVE-2019-9714An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.
CVE-2019-9713An issue was discovered in Joomla! before 3.9.4. The sample data plugins lack ACL checks, allowing unauthorized access.
CVE-2019-9712An issue was discovered in Joomla! before 3.9.4. The JSON handler in com_config lacks input validation, leading to XSS.
CVE-2019-9711An issue was discovered in Joomla! before 3.9.4. The item_title layout in edit views lacks escaping, leading to XSS.
CVE-2019-9644An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious...
CVE-2019-9710An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products. JSON parsing uses a short-...
CVE-2019-9693In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php vi...
CVE-2019-9692class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now