2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-0106Insufficient run protection in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a pri...
CVE-2019-0105Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may ...
CVE-2019-0104Insufficient file protection in uninstall routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an...
CVE-2019-0103Insufficient file protection in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an a...
CVE-2019-0102Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an...
CVE-2019-0101Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to poten...
CVE-2019-8903index.js in Total.js Platform before 3.2.3 allows path traversal.
CVE-2019-8372The LHA.sys driver before 1.1.1811.2101 in LG Device Manager exposes functionality that allows low-privileged users to r...
CVE-2019-6453mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a...
CVE-2019-8902An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the publi...
CVE-2019-8436imcat 4.5 has Stored XSS via the root/run/adm.php fm[instop][note] parameter.
CVE-2019-8435admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
CVE-2019-8434In CmsEasy 7.0, there is XSS via the ckplayer.php autoplay parameter.
CVE-2019-8433JTBC(PHP) 3.0.1.8 allows Arbitrary File Upload via the console/#/console/file/manage.php?type=list URI, as demonstrated ...
CVE-2019-8432In CmsEasy 7.0, there is XSS via the ckplayer.php url parameter.
CVE-2019-8429ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php filter[Query][terms][0][cnj] parameter.
CVE-2019-8428ZoneMinder before 1.32.3 has SQL Injection via the skins/classic/views/control.php groupSql parameter, as demonstrated b...
CVE-2019-8427daemonControl in includes/functions.php in ZoneMinder before 1.32.3 allows command injection via shell metacharacters.
CVE-2019-8426skins/classic/views/controlcap.php in ZoneMinder before 1.32.3 has XSS via the newControl array, as demonstrated by the ...
CVE-2019-8425includes/database.php in ZoneMinder before 1.32.3 has XSS in the construction of SQL-ERR messages.
CVE-2019-8424ZoneMinder before 1.32.3 has SQL Injection via the ajax/status.php sort parameter.
CVE-2019-8423ZoneMinder through 1.32.3 has SQL Injection via the skins/classic/views/events.php filter[Query][terms][0][cnj] paramete...
CVE-2019-8422A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\C...
CVE-2019-8421upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titl...
CVE-2019-8419VNote 2.2 has XSS via a new text note.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now