2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6805 | — | — | 1.1% | Jan 25, 2019 | SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter. |
| CVE-2019-6804 | — | — | 5.3% | Jan 25, 2019 | An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip... |
| CVE-2019-6803 | — | — | 1.9% | Jan 25, 2019 | typora through 0.9.9.20.3 beta has XSS, with resultant remote command execution, via the left outline bar. |
| CVE-2019-6802 | — | — | 3.9% | Jan 25, 2019 | CRLF Injection in pypiserver 1.2.5 and below allows attackers to set arbitrary HTTP headers and possibly conduct XSS att... |
| CVE-2019-6780 | — | — | 4.9% | Jan 24, 2019 | The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost... |
| CVE-2019-6779 | — | — | 0.5% | Jan 24, 2019 | Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links. |
| CVE-2019-6777 | — | — | 1.0% | Jan 24, 2019 | An issue was discovered in ZoneMinder v1.32.3. Reflected XSS exists in web/skins/classic/views/plugin.php via the zm/ind... |
| CVE-2019-6486 | — | — | 4.3% | Jan 24, 2019 | Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 elliptic curves, which allows attackers to cause a ... |
| CVE-2019-6719 | — | — | 1.5% | Jan 23, 2019 | An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_... |
| CVE-2019-6713 | — | — | 2.4% | Jan 23, 2019 | app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by... |
| CVE-2019-6708 | — | — | 1.0% | Jan 23, 2019 | PHPSHE 1.7 has SQL injection via the admin.php?mod=order state parameter. |
| CVE-2019-6707 | — | — | 1.0% | Jan 23, 2019 | PHPSHE 1.7 has SQL injection via the admin.php?mod=product&act=state product_id[] parameter. |
| CVE-2019-6691 | — | — | 1.1% | Jan 23, 2019 | phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related... |
| CVE-2019-6260 | — | — | 3.6% | Jan 22, 2019 | The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-perfor... |
| CVE-2019-6510 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. user_delete in srcpm/app/admin/views.py allows CSR... |
| CVE-2019-6509 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. depart_delete in srcpm/app/admin/views.py allows C... |
| CVE-2019-6508 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. role_perm_delete in srcpm/app/admin/views.py allow... |
| CVE-2019-6507 | — | — | 0.7% | Jan 22, 2019 | An issue was discovered in creditease-sec insight through 2018-09-11. login_user_delete in srcpm/app/admin/views.py allo... |
| CVE-2019-6339 | — | — | 33.2% | Jan 22, 2019 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; A remote code execution vulner... |
| CVE-2019-6503 | — | — | 2.2% | Jan 22, 2019 | There is a deserialization vulnerability in Chatopera cosin v3.10.0. An attacker can execute commands during server-side... |
| CVE-2019-6338 | — | — | 2.3% | Jan 22, 2019 | In Drupal Core versions 7.x prior to 7.62, 8.6.x prior to 8.6.6 and 8.5.x prior to 8.5.9; Drupal core uses the third-par... |
| CVE-2019-6502 | — | — | 2.2% | Jan 22, 2019 | sc_context_create in ctx.c in libopensc in OpenSC 0.19.0 has a memory leak, as demonstrated by a call from eidenv. |
| CVE-2019-6500 | — | — | 4.1% | Jan 21, 2019 | In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a ... |
| CVE-2019-6499 | — | — | 1.5% | Jan 21, 2019 | Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint databas... |
| CVE-2019-6498 | — | — | 5.0% | Jan 21, 2019 | GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now