2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7587 | — | — | 1.5% | Feb 7, 2019 | Bo-blog Wind through 1.6.0-r allows SQL Injection via the admin.php/comments/batchdel/ comID parameter because this para... |
| CVE-2019-7585 | — | — | 1.5% | Feb 7, 2019 | An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Inject... |
| CVE-2019-7582 | — | — | 2.2% | Feb 7, 2019 | The readBytes function in util/read.c in libming through 0.4.8 allows remote attackers to have unspecified impact via a ... |
| CVE-2019-7581 | — | — | 2.1% | Feb 7, 2019 | The parseSWF_ACTIONRECORD function in util/parser.c in libming through 0.4.8 allows remote attackers to have unspecified... |
| CVE-2019-7580 | — | — | 9.9% | Feb 7, 2019 | ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html ali... |
| CVE-2019-7535 | — | — | 1.1% | Feb 7, 2019 | index.php in Gurock TestRail 5.3.0.3603 returns potentially sensitive information for an invalid request, as demonstrate... |
| CVE-2019-7570 | — | — | 0.5% | Feb 7, 2019 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. |
| CVE-2019-7569 | — | — | 0.7% | Feb 7, 2019 | An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super a... |
| CVE-2019-7568 | — | — | 1.5% | Feb 7, 2019 | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate param... |
| CVE-2019-7567 | — | — | 0.8% | Feb 7, 2019 | An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or pass... |
| CVE-2019-7566 | — | — | 0.7% | Feb 7, 2019 | CSZ CMS 1.1.8 has CSRF via admin/users/new/add. |
| CVE-2019-7560 | — | — | 1.0% | Feb 7, 2019 | In parser/btorsmt2.c in Boolector 3.0.0, opening a specially crafted input file leads to a use after free in get_failed_... |
| CVE-2019-7559 | — | — | 0.8% | Feb 7, 2019 | In btor2parser/btor2parser.c in Boolector Btor2Tools before 2019-01-15, opening a specially crafted input file leads to ... |
| CVE-2019-7547 | — | — | 0.7% | Feb 6, 2019 | An issue was discovered in SIDU 6.0. Because the database name is not strictly filtered, the attacker can insert a name ... |
| CVE-2019-7546 | — | — | 0.9% | Feb 6, 2019 | An issue was discovered in SIDU 6.0. The dbs parameter of the conn.php page has a reflected Cross-site Scripting (XSS) v... |
| CVE-2019-7545 | — | — | 0.7% | Feb 6, 2019 | In DbNinja 3.2.7, the Add Host function of the Manage Hosts pages has a Stored Cross-site Scripting (XSS) vulnerability ... |
| CVE-2019-7544 | — | — | 0.7% | Feb 6, 2019 | An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-site Scripti... |
| CVE-2019-7543 | — | — | 3.1% | Feb 6, 2019 | In KindEditor 4.1.11, the php/demo.php content1 parameter has a reflected Cross-site Scripting (XSS) vulnerability. |
| CVE-2019-1003023 | — | — | 1.0% | Feb 6, 2019 | A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/jav... |
| CVE-2019-1003022 | — | — | 0.7% | Feb 6, 2019 | A denial of service vulnerability exists in Jenkins Monitoring Plugin 1.74.0 and earlier in PluginImpl.java that allows ... |
| CVE-2019-1003021 | — | — | 1.1% | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins OpenId Connect Authentication Plugin 1.4 and earlie... |
| CVE-2019-1003020 | — | — | 0.6% | Feb 6, 2019 | A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfig... |
| CVE-2019-1003019 | — | — | 0.9% | Feb 6, 2019 | An session fixation vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in GithubSecurityRealm... |
| CVE-2019-1003018 | — | — | 1.1% | Feb 6, 2019 | An exposure of sensitive information vulnerability exists in Jenkins GitHub Authentication Plugin 0.29 and earlier in Gi... |
| CVE-2019-1003017 | — | — | 0.5% | Feb 6, 2019 | A data modification vulnerability exists in Jenkins Job Import Plugin 3.0 and earlier in JobImportAction.java that allow... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now