2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-9015 | — | — | 1.9% | Feb 22, 2019 | A Path Traversal vulnerability was discovered in MOPCMS through 2018-11-30, leading to deletion of unexpected critical f... |
| CVE-2019-9004 | — | — | 1.5% | Feb 22, 2019 | In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles i... |
| CVE-2019-7729 | — | — | 0.3% | Feb 22, 2019 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, ... |
| CVE-2019-7728 | — | — | 0.5% | Feb 22, 2019 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certif... |
| CVE-2019-9002 | — | — | 2.4% | Feb 22, 2019 | An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote att... |
| CVE-2019-8955 | — | — | 4.6% | Feb 21, 2019 | In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial o... |
| CVE-2019-8985 | — | — | 13.3% | Feb 21, 2019 | On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stac... |
| CVE-2019-8984 | — | — | 0.8% | Feb 21, 2019 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2). |
| CVE-2019-8983 | — | — | 0.8% | Feb 21, 2019 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2). |
| CVE-2019-8982 | — | — | 25.6% | Feb 21, 2019 | com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&... |
| CVE-2019-8979 | — | — | 3.2% | Feb 21, 2019 | Kohana through 3.3.6 has SQL Injection when the order_by() parameter can be controlled. |
| CVE-2019-1000049 | — | — | — | Feb 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-8363. Reason: This candidate is a reservation ... |
| CVE-2019-1000048 | — | — | — | Feb 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-7469. Reason: This candidate is a reservation ... |
| CVE-2019-1000047 | — | — | — | Feb 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-7469. Reason: This candidate is a reservation ... |
| CVE-2019-1000041 | — | — | — | Feb 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-7575, CVE-2019-7577. Reason: This candidate is... |
| CVE-2019-1000030 | — | — | — | Feb 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-7580. Reason: This candidate is a reservation ... |
| CVE-2019-5727 | — | — | 0.7% | Feb 21, 2019 | Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x ... |
| CVE-2019-1003028 | — | — | 0.7% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins JMS Messaging Plugin 1.1.1 and earlier in SSLCertificateAu... |
| CVE-2019-1003027 | — | — | 1.0% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlu... |
| CVE-2019-1003026 | — | — | 0.9% | Feb 20, 2019 | A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in Matter... |
| CVE-2019-8954 | — | — | 2.7% | Feb 20, 2019 | In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id paramet... |
| CVE-2019-8953 | — | — | 52.2% | Feb 20, 2019 | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re... |
| CVE-2019-8950 | — | — | 2.6% | Feb 20, 2019 | The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to log... |
| CVE-2019-8948 | — | — | 3.9% | Feb 20, 2019 | PaperCut MF before 18.3.6 and PaperCut NG before 18.3.6 allow script injection via the user interface, aka PC-15163. |
| CVE-2019-8944 | — | — | 1.5% | Feb 20, 2019 | An Information Exposure issue in the Terraform deployment step in Octopus Deploy before 2019.1.8 (and before 2018.10.4 L... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now