2019 CVE Vulnerabilities
17,620 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-5720 | — | — | 1.5% | Jan 8, 2019 | includes/db/class.reflines_db.inc in FrontAccounting 2.4.6 contains a SQL Injection vulnerability in the reference field... |
| CVE-2019-5489 | — | — | 0.8% | Jan 7, 2019 | The mincore() implementation in mm/mincore.c in the Linux kernel through 4.19.13 allowed local attackers to observe page... |
| CVE-2019-5488 | — | — | 1.2% | Jan 7, 2019 | EARCLINK ESPCMS-P8 has SQL injection in the install_pack/index.php?ac=Member&at=verifyAccount verify_key parameter. inst... |
| CVE-2019-5311 | — | — | 0.7% | Jan 4, 2019 | An issue was discovered in YUNUCMS V1.1.8. app/index/controller/Show.php has an XSS vulnerability via the index.php/inde... |
| CVE-2019-5310 | — | — | 0.7% | Jan 4, 2019 | YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as dem... |
| CVE-2019-5007 | — | — | 1.6% | Jan 3, 2019 | An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is an Out-of-Bounds Read Information Di... |
| CVE-2019-5006 | — | — | 0.9% | Jan 3, 2019 | An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PD... |
| CVE-2019-5005 | — | — | 1.3% | Jan 3, 2019 | An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. They allowed Denial of Service (applicatio... |
| CVE-2019-3905 | — | — | 3.3% | Jan 3, 2019 | Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF. |
| CVE-2019-3575 | — | — | 0.4% | Jan 3, 2019 | Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_... |
| CVE-2019-3701 | — | — | 0.7% | Jan 3, 2019 | An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modificatio... |
| CVE-2019-3580 | — | — | 1.9% | Jan 3, 2019 | OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted ... |
| CVE-2019-3577 | — | — | 1.1% | Jan 2, 2019 | An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection ... |
| CVE-2019-3576 | — | — | 1.5% | Jan 2, 2019 | inxedu through 2018-12-24 has a SQL Injection vulnerability that can lead to information disclosure via the deleteFaveor... |
| CVE-2019-3574 | — | — | 1.2% | Jan 2, 2019 | In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstr... |
| CVE-2019-3573 | — | — | 1.0% | Jan 2, 2019 | In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demons... |
| CVE-2019-3572 | — | — | 1.2% | Jan 2, 2019 | An issue was discovered in libming 0.4.8. There is a heap-based buffer over-read in the function writePNG in the file ut... |
| CVE-2019-3501 | — | — | 2.4% | Jan 2, 2019 | The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag... |
| CVE-2019-3494 | — | — | 1.0% | Jan 1, 2019 | Simply-Blog through 2019-01-01 has SQL Injection via the admin/deleteCategories.php delete parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now