2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-9610An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ direc...
CVE-2019-9609An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ...
CVE-2019-9608An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and ...
CVE-2019-9607PHP Scripts Mall Medical Store Script 3.0.3 allows Path Traversal by navigating to the parent directory of a jpg or png ...
CVE-2019-9606PHP Scripts Mall Personal Video Collection Script 4.0.4 has Stored XSS via the "Update profile" feature.
CVE-2019-1543ChaCha20-Poly1305 is an AEAD cipher, and requires a unique nonce input for every encryption operation. RFC 7539 specifie...
CVE-2019-9603MiniCMS 1.10 allows mc-admin/post.php?state=publish&delete= CSRF to delete articles, a different vulnerability than CVE-...
CVE-2019-9601The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si...
CVE-2019-9600The Olive Tree FTP Server (aka com.theolivetree.ftpserver) application through 1.32 for Android allows remote attackers ...
CVE-2019-9599The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash...
CVE-2019-0200A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which all...
CVE-2019-0187Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can es...
CVE-2019-9595AppCMS 2.0.101 allows XSS via the upload/callback.php params parameter.
CVE-2019-9594BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
CVE-2019-9590An issue was discovered on TENGCONTROL T-920 PLC v5.5 devices. It allows remote attackers to cause a denial of service (...
CVE-2019-3824A flaw was found in the way an LDAP search expression could crash the shared LDAP server process of a samba AD DC in sam...
CVE-2019-9589There is a NULL pointer dereference vulnerability in PSOutputDev::setupResources() located in PSOutputDev.cc in Xpdf 4.0...
CVE-2019-9588There is an Invalid memory access in gAtomicIncrement() located at GMutex.h in Xpdf 4.01. It can be triggered by sending...
CVE-2019-9587There is a stack consumption issue in md5Round1() located in Decrypt.cc in Xpdf 4.01. It can be triggered by sending a c...
CVE-2019-9578In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back...
CVE-2019-9555Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2...
CVE-2019-8336HashiCorp Consul (and Consul Enterprise) 1.4.x before 1.4.3 allows a client to bypass intended access restrictions and o...
CVE-2019-0743A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i...
CVE-2019-0742A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided i...
CVE-2019-0741An information disclosure vulnerability exists in the way Azure IoT Java SDK logs sensitive information, aka 'Azure IoT ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now