2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9125 | — | — | 3.0% | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a stack-based buffer ove... |
| CVE-2019-9124 | — | — | 2.2% | Feb 25, 2019 | An issue was discovered on D-Link DIR-878 1.12B01 devices. At the /HNAP1 URI, an attacker can log in with a blank passwo... |
| CVE-2019-9115 | — | — | 2.3% | Feb 25, 2019 | In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage. |
| CVE-2019-9114 | — | — | 1.3% | Feb 25, 2019 | Ming (aka libming) 0.4.8 has an out of bounds write vulnerability in the function strcpyext() in the decompile.c file in... |
| CVE-2019-9113 | — | — | 1.4% | Feb 25, 2019 | Ming (aka libming) 0.4.8 has a NULL pointer dereference in the function getString() in the decompile.c file in libutil.a... |
| CVE-2019-9112 | — | — | 0.8% | Feb 25, 2019 | The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer o... |
| CVE-2019-9111 | — | — | 0.8% | Feb 25, 2019 | The msm gpu driver for custom Linux kernels on the Xiaomi perseus-p-oss MIX 3 device through 2018-11-26 has an integer o... |
| CVE-2019-9110 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/pos... |
| CVE-2019-9109 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.ph... |
| CVE-2019-9108 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php. |
| CVE-2019-9107 | — | — | 0.9% | Feb 25, 2019 | XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imag... |
| CVE-2019-9081 | — | — | — | Feb 24, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2019-9078 | — | — | 0.6% | Feb 24, 2019 | zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-ca... |
| CVE-2019-8375 | — | — | 16.1% | Feb 24, 2019 | The UIProcess subsystem in WebKit, as used in WebKitGTK through 2.23.90 and WebKitGTK+ through 2.22.6 and other products... |
| CVE-2019-9066 | — | — | 0.6% | Feb 23, 2019 | PHP Scripts Mall PHP Appointment Booking Script 3.0.3 allows HTML injection in a user profile. |
| CVE-2019-9065 | — | — | 0.9% | Feb 23, 2019 | PHP Scripts Mall Custom T-Shirt Ecommerce Script 3.1.1 allows parameter tampering of the payment amount. |
| CVE-2019-9064 | — | — | 1.9% | Feb 23, 2019 | PHP Scripts Mall Cab Booking Script 1.0.3 allows Directory Traversal into the parent directory of a jpg or png file. |
| CVE-2019-9063 | — | — | 0.9% | Feb 23, 2019 | PHP Scripts Mall Auction website script 2.0.4 allows parameter tampering of the payment amount. |
| CVE-2019-9062 | — | — | 0.5% | Feb 23, 2019 | PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php. |
| CVE-2019-9047 | — | — | 1.5% | Feb 23, 2019 | GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled. |
| CVE-2019-9052 | — | — | 0.6% | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete pictures via a /admin.php?act... |
| CVE-2019-9051 | — | — | 0.6% | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete articles via a /admin.php?act... |
| CVE-2019-9050 | — | — | 2.0% | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. It allows administrators to execute arbitrary code by using action=installm... |
| CVE-2019-9049 | — | — | 0.6% | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete modules via a /admin.php?acti... |
| CVE-2019-9048 | — | — | 0.6% | Feb 23, 2019 | An issue was discovered in Pluck 4.7.9-dev1. There is a CSRF vulnerability that can delete a theme (aka topic) via a /ad... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now