2019 CVE Vulnerabilities

17,620 CVEs published in 2019.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2019-7721lib/NCCms.class.php in nc-cms 3.5 allows upload of .php files via the index.php?action=save name and editordata paramete...
CVE-2019-7720taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making...
CVE-2019-7719Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a conte...
CVE-2019-7718An issue was discovered in Metinfo 6.x. An attacker can leverage a race condition in the backend database backup functio...
CVE-2019-7699A heap-based buffer over-read occurs in AP4_BitStream::WriteBytes in Codecs/Ap4BitStream.cpp in Bento4 v1.5.1-627. Remot...
CVE-2019-7698An issue was discovered in AP4_Array<AP4_CttsTableEntry>::EnsureCapacity in Core/Ap4Array.h in Bento4 1.5.1-627. Crafted...
CVE-2019-7697An issue was discovered in Bento4 v1.5.1-627. There is an assertion failure in AP4_AtomListWriter::Action in Core/Ap4Ato...
CVE-2019-7693Axios Italia Axios RE 1.7.0/7.0.0 devices have XSS via the RELogOff.aspx Error_Parameters parameter. In some situations,...
CVE-2019-7692install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value becaus...
CVE-2019-7684inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code l...
CVE-2019-7678A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include...
CVE-2019-7677XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
CVE-2019-7676A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin pas...
CVE-2019-7675An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. The default management application is delivered over cleart...
CVE-2019-7674An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. /admin/access accepts a request to set the "aaaaa" password...
CVE-2019-7673An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. Administrator Credentials are stored in the 13-character DE...
CVE-2019-7663An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibT...
CVE-2019-7659Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibl...
CVE-2019-7651EPP.sys in Emsisoft Anti-Malware prior to version 2018.12 allows an attacker to bypass ACLs because Interpreted Device C...
CVE-2019-7648controller/fetchpwd.php and controller/doAction.php in Hotels_Server through 2018-11-05 rely on base64 in an attempt to ...
CVE-2019-7639An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsiss...
CVE-2019-7632LifeSize Team, Room, Passport, and Networker 220 devices allow Authenticated Remote OS Command Injection, as demonstrate...
CVE-2019-6242Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuratio...
CVE-2019-7628Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for ma...
CVE-2019-7401NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a speci...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now