2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-7169 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7168 | — | — | 0.6% | Jan 29, 2019 | A stored-self XSS exists in Croogo through v3.0.5, allowing an attacker to execute HTML or JavaScript code in a vulnerab... |
| CVE-2019-7160 | — | — | 3.4% | Jan 29, 2019 | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php,... |
| CVE-2019-7156 | — | — | 1.3% | Jan 29, 2019 | In libdoc through 2019-01-28, calcFileBlockOffset in ole.c allows division by zero. |
| CVE-2019-7149 | — | — | 2.2% | Jan 29, 2019 | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0... |
| CVE-2019-7148 | — | — | 1.6% | Jan 29, 2019 | An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfu... |
| CVE-2019-7147 | — | — | 0.8% | Jan 29, 2019 | A buffer over-read exists in the function crc64ib in crc64.c in nasmlib in Netwide Assembler (NASM) 2.14rc16. A crafted ... |
| CVE-2019-7146 | — | — | 1.5% | Jan 29, 2019 | In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attacke... |
| CVE-2019-6992 | — | — | 0.9% | Jan 28, 2019 | A stored-self XSS exists in web/skins/classic/views/controlcaps.php of ZoneMinder through 1.32.3, allowing an attacker t... |
| CVE-2019-6991 | — | — | 3.3% | Jan 28, 2019 | A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder... |
| CVE-2019-6990 | — | — | 0.7% | Jan 28, 2019 | A stored-self XSS exists in web/skins/classic/views/zones.php of ZoneMinder through 1.32.3, allowing an attacker to exec... |
| CVE-2019-6988 | — | — | 1.7% | Jan 28, 2019 | An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive ... |
| CVE-2019-6986 | — | — | 3.0% | Jan 28, 2019 | SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leadi... |
| CVE-2019-6985 | — | — | 1.4% | Jan 28, 2019 | An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application coul... |
| CVE-2019-6984 | — | — | 1.1% | Jan 28, 2019 | An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application coul... |
| CVE-2019-6983 | — | — | 1.1% | Jan 28, 2019 | An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application coul... |
| CVE-2019-6982 | — | — | 2.5% | Jan 28, 2019 | An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application coul... |
| CVE-2019-6979 | — | — | 2.1% | Jan 28, 2019 | An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad... |
| CVE-2019-6978 | — | — | 4.4% | Jan 28, 2019 | The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, a... |
| CVE-2019-6977 | — | — | 65.1% | Jan 27, 2019 | gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch funct... |
| CVE-2019-6703 | — | — | 26.1% | Jan 27, 2019 | Incorrect access control in migla_ajax_functions.php in the Calmar Webmedia Total Donations plugin through 2.0.5 for Wor... |
| CVE-2019-6976 | — | — | 2.3% | Jan 26, 2019 | libvips before 8.7.4 generates output images from uninitialized memory locations when processing corrupted input image d... |
| CVE-2019-6799 | — | — | 15.6% | Jan 26, 2019 | An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, ... |
| CVE-2019-6798 | — | — | 3.9% | Jan 26, 2019 | An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can ... |
| CVE-2019-6966 | — | — | 1.2% | Jan 25, 2019 | An issue was discovered in Bento4 1.5.1-628. The AP4_ElstAtom class in Core/Ap4ElstAtom.cpp has an attempted excessive m... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now