2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-6244 | — | — | 0.5% | Jan 12, 2019 | An issue was discovered in UsualToolCMS 8.0. cmsadmin/a_sqlbackx.php?t=sql allows CSRF attacks that can execute SQL stat... |
| CVE-2019-6243 | — | — | 0.7% | Jan 12, 2019 | Frog CMS 0.9.5 allows XSS via the forgot password page (aka the /admin/?/login/forgot URI). |
| CVE-2019-6138 | — | — | 1.5% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Memory_malloc and Memory_calloc in hal/memory/lib_memory.c have memory le... |
| CVE-2019-6137 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in lib60870 2.1.1. LinkLayer_setAddress in link_layer/link_layer.c has a NULL pointer dereferenc... |
| CVE-2019-6136 | — | — | 1.5% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Ethernet_setProtocolFilter in hal/ethernet/linux/ethernet_linux.c has a S... |
| CVE-2019-6135 | — | — | 1.7% | Jan 11, 2019 | An issue has been found in libIEC61850 v1.3.1. Memory_malloc in hal/memory/lib_memory.c has a memory leak when called fr... |
| CVE-2019-6133 | — | — | 0.4% | Jan 11, 2019 | In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and... |
| CVE-2019-6132 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in Bento4 v1.5.1-627. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStrea... |
| CVE-2019-6131 | — | — | 1.5% | Jan 11, 2019 | svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, ... |
| CVE-2019-6130 | — | — | 1.6% | Jan 11, 2019 | Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. Thi... |
| CVE-2019-6127 | — | — | 1.5% | Jan 11, 2019 | An issue was discovered in XiaoCms 20141229. It allows admin/index.php?c=database table[] SQL injection. This can be use... |
| CVE-2019-6126 | — | — | 1.4% | Jan 11, 2019 | The Admin Panel of PHP Scripts Mall Advance Peer to Peer MLM Script v1.7.0 allows remote attackers to bypass intended ac... |
| CVE-2019-0088 | — | — | 0.3% | Jan 10, 2019 | Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated use... |
| CVE-2019-5893 | — | — | 24.7% | Jan 10, 2019 | Nelson Open Source ERP v6.3.1 allows SQL Injection via the db/utils/query/data.xml query parameter. |
| CVE-2019-5892 | — | — | 2.7% | Jan 10, 2019 | bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x before 5.0.2, and 6.x bef... |
| CVE-2019-5887 | — | — | 1.5% | Jan 10, 2019 | An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not ... |
| CVE-2019-5886 | — | — | 1.0% | Jan 10, 2019 | An issue was discovered in ShopXO 1.2.0. In the application\install\controller\Index.php file, there is no validation lo... |
| CVE-2019-5882 | — | — | 2.5% | Jan 9, 2019 | Irssi 1.1.x before 1.1.2 has a use after free when hidden lines are expired from the scroll buffer. |
| CVE-2019-3498 | — | — | 3.7% | Jan 9, 2019 | In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, an Improper Neutralization of Special Elem... |
| CVE-2019-5748 | — | — | 1.7% | Jan 9, 2019 | In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks. |
| CVE-2019-5725 | — | — | 1.5% | Jan 8, 2019 | qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstr... |
| CVE-2019-5721 | — | — | 0.9% | Jan 8, 2019 | In Wireshark 2.4.0 to 2.4.11, the ENIP dissector could crash. This was addressed in epan/dissectors/packet-enip.c by cha... |
| CVE-2019-5719 | — | — | 0.8% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors... |
| CVE-2019-5718 | — | — | 1.4% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was add... |
| CVE-2019-5717 | — | — | 1.4% | Jan 8, 2019 | In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now