2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-1000022 | — | — | 0.6% | Feb 4, 2019 | Taoensso Sente version Prior to version 1.14.0 contains a Cross Site Request Forgery (CSRF) vulnerability in WebSocket h... |
| CVE-2019-1000021 | — | — | 2.3% | Feb 4, 2019 | slixmpp version before commit 7cd73b594e8122dddf847953fcfc85ab4d316416 contains an incorrect Access Control vulnerabilit... |
| CVE-2019-1000017 | — | — | 1.0% | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component t... |
| CVE-2019-1000016 | — | — | 1.1% | Feb 4, 2019 | FFMPEG version 4.1 contains a CWE-129: Improper Validation of Array Index vulnerability in libavcodec/cbs_av1.c that can... |
| CVE-2019-1000015 | — | — | 0.8% | Feb 4, 2019 | Chamilo Chamilo-lms version 1.11.8 and earlier contains a Cross Site Scripting (XSS) vulnerability in main/messages/new_... |
| CVE-2019-1000014 | — | — | 1.8% | Feb 4, 2019 | Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification t... |
| CVE-2019-1000013 | — | — | 0.9% | Feb 4, 2019 | Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verif... |
| CVE-2019-1000012 | — | — | 0.9% | Feb 4, 2019 | Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verificati... |
| CVE-2019-1000011 | — | — | 1.0% | Feb 4, 2019 | API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations ... |
| CVE-2019-1000010 | — | — | 0.9% | Feb 4, 2019 | phpIPAM version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in subnet-scan-telnet.php that can... |
| CVE-2019-1000009 | — | — | 1.3% | Feb 4, 2019 | Helm ChartMuseum version >=0.1.0 and < 0.8.1 contains a CWE-22: Improper Limitation of a Pathname to a Restricted Direct... |
| CVE-2019-1000008 | — | — | 1.5% | Feb 4, 2019 | All versions of Helm between Helm >=2.0.0 and < 2.12.2 contains a CWE-22: Improper Limitation of a Pathname to a Restric... |
| CVE-2019-1000007 | — | — | 1.2% | Feb 4, 2019 | aioxmpp version 0.10.2 and earlier contains a Improper Handling of Structural Elements vulnerability in Stanza Parser, r... |
| CVE-2019-1000005 | — | — | 2.1% | Feb 4, 2019 | mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method ... |
| CVE-2019-1000004 | — | — | 0.8% | Feb 4, 2019 | yugandhargangu JspMyAdmin2 version 1.0.6 and earlier contains a Cross Site Scripting (XSS) vulnerability in sidebar and ... |
| CVE-2019-1000003 | — | — | 0.8% | Feb 4, 2019 | MapSVG MapSVG Lite version 3.2.3 contains a Cross Site Request Forgery (CSRF) vulnerability in REST endpoint /wp-admin/a... |
| CVE-2019-1000002 | — | — | 1.1% | Feb 4, 2019 | Gitea version 1.6.2 and earlier contains a Incorrect Access Control vulnerability in Delete/Edit file functionallity tha... |
| CVE-2019-1000001 | — | — | 1.7% | Feb 4, 2019 | TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared passwor... |
| CVE-2019-7352 | — | — | 0.9% | Feb 4, 2019 | Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, as the view 'state' (aka Run State) (state... |
| CVE-2019-7351 | — | — | 1.2% | Feb 4, 2019 | Log Injection exists in ZoneMinder through 1.32.3, as an attacker can entice the victim to visit a specially crafted lin... |
| CVE-2019-7350 | — | — | 1.0% | Feb 4, 2019 | Session fixation exists in ZoneMinder through 1.32.3, as an attacker can fixate his own session cookies to the next logg... |
| CVE-2019-7349 | — | — | 0.9% | Feb 4, 2019 | Reflected Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or JavaSc... |
| CVE-2019-7348 | — | — | 0.8% | Feb 4, 2019 | Self - Stored Cross Site Scripting (XSS) exists in ZoneMinder through 1.32.3, allowing an attacker to execute HTML or Ja... |
| CVE-2019-7347 | — | — | 0.9% | Feb 4, 2019 | A Time-of-check Time-of-use (TOCTOU) Race Condition exists in ZoneMinder through 1.32.3 as a session remains active for ... |
| CVE-2019-7346 | — | — | 0.7% | Feb 4, 2019 | A CSRF check issue exists in ZoneMinder through 1.32.3 as whenever a CSRF check fails, a callback function is called dis... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now