2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-8334An issue was discovered in SchoolCMS 2.3.1. There is an XSS vulnerability via index.php?a=Index&c=Channel&m=Home&viewid=...
CVE-2019-8308Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows at...
CVE-2019-7550In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" func...
CVE-2019-7744An issue was discovered in Joomla! before 3.9.3. Inadequate filtering on URL fields in various core components could lea...
CVE-2019-7743An issue was discovered in Joomla! before 3.9.3. The phar:// stream wrapper can be used for objection injection attacks ...
CVE-2019-7742An issue was discovered in Joomla! before 3.9.3. A combination of specific web server configurations, in connection with...
CVE-2019-7741An issue was discovered in Joomla! before 3.9.3. Inadequate checks at the Global Configuration helpurl settings allowed ...
CVE-2019-7740An issue was discovered in Joomla! before 3.9.3. Inadequate parameter handling in JavaScript code (core.js writeDynaList...
CVE-2019-7739An issue was discovered in Joomla! before 3.9.3. The "No Filtering" textfilter overrides child settings in the Global Co...
CVE-2019-7753Verydows 2.0 has XSS via the index.php?m=api&c=stats&a=count referrer parameter.
CVE-2019-5596In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS...
CVE-2019-5595In FreeBSD before 11.2-STABLE(r343782), 11.2-RELEASE-p9, 12.0-STABLE(r343781), and 12.0-RELEASE-p3, kernel callee-save r...
CVE-2019-3923Nessus versions 8.2.1 and earlier were found to contain a stored XSS vulnerability due to improper validation of user-su...
CVE-2019-7748_includes\online.php in DbNinja 3.2.7 allows XSS via the data.php task parameter if _users/admin/tasks.php exists.
CVE-2019-7747DbNinja 3.2.7 allows session fixation via the data.php sessid parameter.
CVE-2019-7738C.P.Sub before 5.3 allows CSRF via a manage.php?p=article_del&id= URI.
CVE-2019-7737A CSRF vulnerability was found in Verydows v2.0 that can add an admin account via index.php?m=backend&c=admin&a=add&step...
CVE-2019-6489Certain Lexmark CX, MX, X, XC, XM, XS, and 6500e devices before 2019-02-11 allow remote attackers to erase stored shortc...
CVE-2019-7736D-Link DIR-600M C1 3.04 devices allow authentication bypass via a direct request to the wan.htm page. NOTE: this may ove...
CVE-2019-7733In Live555 0.95, there is a buffer overflow via a large integer in a Content-Length HTTP header because handleRequestByt...
CVE-2019-7732In Live555 0.95, a setup packet can cause a memory leak leading to DoS because, when there are multiple instances of a s...
CVE-2019-7731MyWebSQL 3.7 has a remote code execution (RCE) vulnerability after an attacker writes shell code into the database, and ...
CVE-2019-7730MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&type=datab...
CVE-2019-7722PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowi...
CVE-2019-6975Django 1.11.x before 1.11.19, 2.0.x before 2.0.11, and 2.1.x before 2.1.6 allows Uncontrolled Memory Consumption via a m...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now