2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9688 | — | — | 0.7% | Mar 11, 2019 | sftnow through 2018-12-29 allows index.php?g=Admin&m=User&a=add_post CSRF to add an admin account. |
| CVE-2019-9687 | — | — | 2.2% | Mar 11, 2019 | PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. |
| CVE-2019-9659 | — | — | 1.3% | Mar 11, 2019 | The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, ... |
| CVE-2019-9675 | — | — | 6.0% | Mar 11, 2019 | An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has... |
| CVE-2019-9662 | — | — | 1.7% | Mar 11, 2019 | An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.ph... |
| CVE-2019-9661 | — | — | 0.7% | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/system_manage/user_config_edit.html "value" parameter, |
| CVE-2019-9660 | — | — | 0.7% | Mar 11, 2019 | Stored XSS exists in YzmCMS 5.2 via the admin/category/edit.html "catname" parameter. |
| CVE-2019-9658 | — | — | 3.7% | Mar 11, 2019 | Checkstyle before 8.18 loads external DTDs by default. |
| CVE-2019-9652 | — | — | 0.6% | Mar 11, 2019 | There is a CSRF in SDCMS V1.7 via an m=admin&c=theme&a=edit request. It allows PHP code injection by providing a filenam... |
| CVE-2019-9651 | — | — | 2.6% | Mar 11, 2019 | An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's... |
| CVE-2019-9650 | — | — | 3.4% | Mar 11, 2019 | An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name... |
| CVE-2019-9646 | — | — | 1.4% | Mar 10, 2019 | The Contact Form Email plugin before 1.2.66 for WordPress allows wp-admin/admin.php item XSS, related to cp_admin_int_ed... |
| CVE-2019-9580 | — | — | 3.0% | Mar 9, 2019 | In st2web in StackStorm Web UI before 2.9.3 and 2.10.x before 2.10.3, it is possible to bypass the CORS protection mecha... |
| CVE-2019-9637 | — | — | 7.2% | Mar 9, 2019 | An issue was discovered in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3.x before 7.3.3. Due to the way rename() acros... |
| CVE-2019-8280 | — | — | 4.2% | Mar 8, 2019 | UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially re... |
| CVE-2019-8270 | — | — | 1.9% | Mar 8, 2019 | UltraVNC revision 1210 has out-of-bounds read vulnerability in VNC client code inside Ultra decoder, which results in a ... |
| CVE-2019-8267 | — | — | 1.9% | Mar 8, 2019 | UltraVNC revision 1207 has out-of-bounds read vulnerability in VNC client code inside TextChat module, which results in ... |
| CVE-2019-8266 | — | — | 2.8% | Mar 8, 2019 | UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of ClientConnecti... |
| CVE-2019-8265 | — | — | 3.1% | Mar 8, 2019 | UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macr... |
| CVE-2019-8264 | — | — | 3.1% | Mar 8, 2019 | UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially... |
| CVE-2019-9633 | — | — | 2.3% | Mar 8, 2019 | gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a con... |
| CVE-2019-9632 | — | — | 39.9% | Mar 8, 2019 | ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because t... |
| CVE-2019-9631 | — | — | 3.5% | Mar 8, 2019 | Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. |
| CVE-2019-9598 | — | — | 0.5% | Mar 7, 2019 | An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account... |
| CVE-2019-9185 | — | — | 2.7% | Mar 7, 2019 | Controller/Async/FilesystemManager.php in the filemanager in Bolt before 3.6.5 allows remote attackers to execute arbitr... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now