2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8418 | — | — | 1.3% | Feb 17, 2019 | SeaCMS 7.2 mishandles member.php?mod=repsw4 requests. |
| CVE-2019-7649 | — | — | 0.9% | Feb 17, 2019 | global.encryptPassword in bootstrap/global.js in CMSWing 1.3.7 relies on multiple MD5 operations for password hashing. |
| CVE-2019-8413 | — | — | 0.4% | Feb 17, 2019 | On Xiaomi MIX 2 devices with the 4.4.78 kernel, a NULL pointer dereference in the ioctl interface of the device file /de... |
| CVE-2019-8412 | — | — | 2.9% | Feb 17, 2019 | FeiFeiCms 4.0.181010 on Windows allows remote attackers to read or delete arbitrary files via index.php?s=Admin-Data-Dow... |
| CVE-2019-8411 | — | — | 2.7% | Feb 17, 2019 | admin/dl_data.php in zzcms 2018 (2018-10-19) allows remote attackers to delete arbitrary files via action=del&filename=.... |
| CVE-2019-8408 | — | — | 1.2% | Feb 17, 2019 | OneFileCMS 3.6.13 allows remote attackers to modify onefilecms.php by clicking the Copy button twice. |
| CVE-2019-8407 | — | — | 1.5% | Feb 17, 2019 | HongCMS 3.0.0 allows arbitrary file read and write operations via a ../ in the filename parameter to the admin/index.php... |
| CVE-2019-8393 | — | — | 1.1% | Feb 17, 2019 | Hotels_Server through 2018-11-05 has SQL Injection via the API because the controller/api/login.php telephone parameter ... |
| CVE-2019-8400 | — | — | 1.3% | Feb 17, 2019 | ORY Hydra before v1.0.0-rc.3+oryOS.9 has Reflected XSS via the oauth2/fallbacks/error error_hint parameter. |
| CVE-2019-8398 | — | — | 1.2% | Feb 17, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_get_size in H... |
| CVE-2019-8397 | — | — | 1.2% | Feb 17, 2019 | An issue was discovered in the HDF HDF5 1.10.4 library. There is an out of bounds read in the function H5T_close_real in... |
| CVE-2019-8396 | — | — | 1.3% | Feb 17, 2019 | A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF HDF5 through 1.10.4 library allows attackers to cause ... |
| CVE-2019-8395 | — | — | 7.1% | Feb 17, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 ... |
| CVE-2019-8392 | — | — | 2.2% | Feb 17, 2019 | An issue was discovered on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing rem... |
| CVE-2019-7399 | — | — | 0.7% | Feb 17, 2019 | Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pag... |
| CVE-2019-8382 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in the function AP4_List:Find located in ... |
| CVE-2019-8380 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A NULL pointer dereference occurs in AP4_Track::GetSampleIndexForTimeStampM... |
| CVE-2019-8378 | — | — | 1.6% | Feb 17, 2019 | An issue was discovered in Bento4 1.5.1-628. A heap-based buffer over-read exists in AP4_BitStream::ReadBytes() in Codec... |
| CVE-2019-8363 | — | — | 0.8% | Feb 16, 2019 | Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value. |
| CVE-2019-8362 | — | — | 1.5% | Feb 16, 2019 | DedeCMS through V5.7SP2 allows arbitrary file upload in dede/album_edit.php or dede/album_add.php, as demonstrated by a ... |
| CVE-2019-8361 | — | — | 0.9% | Feb 16, 2019 | PHP Scripts Mall Responsive Video News Script has XSS via the Search Bar. This might, for example, be leveraged for HTML... |
| CVE-2019-8360 | — | — | 2.0% | Feb 16, 2019 | Themerig Find a Place CMS Directory 1.5 has SQL Injection via the find/assets/external/data_2.php cate parameter. |
| CVE-2019-8358 | — | — | 1.5% | Feb 16, 2019 | In Hiawatha before 10.8.4, a remote attacker is able to do directory traversal if AllowDotFiles is enabled. |
| CVE-2019-8357 | — | — | 1.6% | Feb 15, 2019 | An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c allows a NULL pointer dereference. |
| CVE-2019-8356 | — | — | 1.8% | Feb 15, 2019 | An issue was discovered in SoX 14.4.2. One of the arguments to bitrv2 in fft4g.c is not guarded, such that it can lead t... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now