2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8261 | — | — | 2.2% | Mar 5, 2019 | UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multipl... |
| CVE-2019-8260 | — | — | 2.3% | Mar 5, 2019 | UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication o... |
| CVE-2019-9572 | — | — | 2.1% | Mar 5, 2019 | SchoolCMS version 2.3.1 allows file upload via the theme upload feature at admin.php?m=admin&c=theme&a=upload by using t... |
| CVE-2019-9570 | — | — | 0.7% | Mar 5, 2019 | An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/system_manage/save.html URI, ... |
| CVE-2019-6235 | — | — | 2.1% | Mar 4, 2019 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.... |
| CVE-2019-6206 | — | — | 1.5% | Mar 4, 2019 | An issue existed with autofill resuming after it was canceled. The issue was addressed with improved state management. T... |
| CVE-2019-9566 | — | — | 1.5% | Mar 4, 2019 | FlarumChina v0.1.0-beta.7C has SQL injection via a /?q= request. |
| CVE-2019-9565 | — | — | 2.1% | Mar 4, 2019 | Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal N... |
| CVE-2019-9563 | — | — | 1.5% | Mar 4, 2019 | In BlueMind 3.5.x before 3.5.11 Hotfix 7 and 4.x before 4.0-beta3, the contact application mishandles temporary uploads. |
| CVE-2019-9552 | — | — | 2.0% | Mar 4, 2019 | Eloan V3.0 through 2018-09-20 allows remote attackers to list files via a direct request to the p2p/api/ or p2p/lib/ or ... |
| CVE-2019-9551 | — | — | 0.6% | Mar 4, 2019 | An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS. |
| CVE-2019-9550 | — | — | 0.6% | Mar 3, 2019 | DhCms through 2017-09-18 has admin.php?r=admin/Index/index XSS. |
| CVE-2019-9549 | — | — | 0.7% | Mar 3, 2019 | An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=user&act=addnew URI, as demonstr... |
| CVE-2019-8279 | — | — | 0.8% | Mar 2, 2019 | Multiple stored XSS in Vanilla Forums before 2.5 allow remote attackers to inject arbitrary JavaScript code into any mes... |
| CVE-2019-8278 | — | — | 1.9% | Mar 2, 2019 | Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution. |
| CVE-2019-9547 | — | — | 1.5% | Mar 1, 2019 | In Storage Performance Development Kit (SPDK) before 19.01, a malicious vhost client (i.e., virtual machine) could caref... |
| CVE-2019-9546 | — | — | 2.8% | Mar 1, 2019 | SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service. |
| CVE-2019-9545 | — | — | 1.8% | Mar 1, 2019 | An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2S... |
| CVE-2019-9544 | — | — | 1.6% | Mar 1, 2019 | An issue was discovered in Bento4 1.5.1-628. An out of bounds write occurs in AP4_CttsTableEntry::AP4_CttsTableEntry() l... |
| CVE-2019-9543 | — | — | 3.3% | Mar 1, 2019 | An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBI... |
| CVE-2019-9484 | — | — | 1.5% | Mar 1, 2019 | The Glen Dimplex Deutschland GmbH implementation of the Carel pCOWeb configuration tool allows remote attackers to obtai... |
| CVE-2019-9483 | — | — | 0.6% | Mar 1, 2019 | Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or inser... |
| CVE-2019-9482 | — | — | 0.7% | Mar 1, 2019 | In MISP 2.4.102, an authenticated user can view sightings that they should not be eligible for. Exploiting this requires... |
| CVE-2019-2001 | — | — | 0.2% | Feb 28, 2019 | The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional e... |
| CVE-2019-2000 | — | — | 0.7% | Feb 28, 2019 | In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local ... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now