2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-19317CRITICAL9.8lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which al...
CVE-2019-19601HIGH7.8OpenDetex 2.8.5 has a Buffer Overflow in TexOpen in detex.l because of an incorrect sprintf.
CVE-2019-19598HIGH8.8D-Link DAP-1860 devices before v1.04b03 Beta allow access to administrator functions without authentication via the HNAP...
CVE-2019-19597HIGH8.8D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via sh...
CVE-2019-19589CRITICAL9.8The Lever PDF Embedder plugin 4.4 for WordPress does not block the distribution of polyglot PDF documents that are valid...
CVE-2019-19596MEDIUM5.4GitBook through 2.6.9 allows XSS via a local .md file.
CVE-2019-19590HIGH7.8In radare2 through 4.0, there is an integer overflow for the variable new_token_size in the function r_asm_massemble at ...
CVE-2019-19588HIGH7.5The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a ...
CVE-2019-19553HIGH7.5In Wireshark 3.0.0 to 3.0.6 and 2.6.0 to 2.6.12, the CMS dissector could crash. This was addressed in epan/dissectors/as...
CVE-2019-19587MEDIUM6.1In WSO2 Enterprise Integrator 6.5.0, reflected XSS occurs when updating the message processor configuration from the sou...
CVE-2019-19522HIGH7.8OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to beco...
CVE-2019-19521CRITICAL9.8libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiu...
CVE-2019-19520HIGH7.8xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH envir...
CVE-2019-19519HIGH7.8In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is ...
CVE-2019-19579MEDIUM6.8An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where...
CVE-2019-16753HIGH7.5An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. The content to be signed is...
CVE-2019-16752MEDIUM4.3An issue was discovered in Decentralized Anonymous Payment System (DAPS) through 2019-08-26. It is possible to force wal...
CVE-2019-11216MEDIUM6.5BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XM...
CVE-2019-19364HIGH7.8A weak malicious user can escalate its privilege whenever CatalystProductionSuite.2019.1.exe (version 1.1.0.21) and Cata...
CVE-2019-19229MEDIUM6.5admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= D...
CVE-2019-19228CRITICAL9.8Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password f...
CVE-2019-19133MEDIUM6.1The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page requ...
CVE-2019-19576CRITICAL9.8class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an...
CVE-2019-18347MEDIUM5.4A stored XSS issue was discovered in DAViCal through 1.1.8. It does not adequately sanitize output of various fields tha...
CVE-2019-18346HIGH8.8A CSRF issue was discovered in DAViCal through 1.1.8. If an authenticated user visits an attacker-controlled webpage, th...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now