2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-8261UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multipl...
CVE-2019-8260UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication o...
CVE-2019-9572SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using t...
CVE-2019-9570An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, ...
CVE-2019-6235A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14....
CVE-2019-6206An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. T...
CVE-2019-9566FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request.
CVE-2019-9565Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal N...
CVE-2019-9563In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads.
CVE-2019-9552Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or ...
CVE-2019-9551An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS.
CVE-2019-9550DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS.
CVE-2019-9549An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstr...
CVE-2019-8279Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any mes...
CVE-2019-8278Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
CVE-2019-9547In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could caref...
CVE-2019-9546SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
CVE-2019-9545An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2S...
CVE-2019-9544An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() l...
CVE-2019-9543An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBI...
CVE-2019-9484The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtai...
CVE-2019-9483Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or inser...
CVE-2019-9482In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires...
CVE-2019-2001The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional e...
CVE-2019-2000In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local ...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now