2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18925CRITICAL9.8Systematic IRIS WebForms 5.4 and its functionalities can be accessed and used without any form of authentication.
CVE-2019-18924MEDIUM5.3Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ....
CVE-2019-18655CRITICAL9.8File Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnera...
CVE-2019-17237HIGH8.8includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows CSRF.
CVE-2019-17236MEDIUM6.1includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress is vulnerable to stored XSS.
CVE-2019-17235MEDIUM5.3includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows information disclosure.
CVE-2019-17234HIGH7.5includes/class-coming-soon-creator.php in the igniteup plugin through 3.4 for WordPress allows unauthenticated arbitrary...
CVE-2019-4652HIGH7.1IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Wind...
CVE-2019-18848HIGH7.5The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
CVE-2019-18817HIGH7.5Istio 1.3.x before 1.3.5 allows Denial of Service because continue_on_listener_filters_timeout is set to True, a related...
CVE-2019-18658CRITICAL9.8In Helm 2.x before 2.15.2, commands that deal with loading a chart as a directory or packaging a chart provide an opport...
CVE-2019-18882MEDIUM6.1WSO2 IS as Key Manager 5.7.0 allows stored XSS in download-userinfo.jag because Content-Type is mishandled.
CVE-2019-18881MEDIUM6.1WSO2 IS as Key Manager 5.7.0 allows unauthenticated reflected XSS in the dashboard user profile.
CVE-2019-18874HIGH7.5psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a wh...
CVE-2019-18873CRITICAL9FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An ...
CVE-2019-18862HIGH7.8maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
CVE-2019-18857HIGH7.5darylldoyle svg-sanitizer before 0.12.0 mishandles script and data values in attributes, as demonstrated by unexpected w...
CVE-2019-18856HIGH7.5A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to...
CVE-2019-18855HIGH7.5A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to p...
CVE-2019-18854HIGH7.5A Denial Of Service vulnerability exists in the safe-svg (aka Safe SVG) plugin through 1.9.4 for WordPress, related to u...
CVE-2019-18853MEDIUM6.5ImageMagick before 7.0.9-0 allows remote attackers to cause a denial of service because XML_PARSE_HUGE is not properly r...
CVE-2019-18852CRITICAL9.8Certain D-Link devices have a hardcoded Alphanetworks user account with TELNET access because of /etc/config/image_sign ...
CVE-2019-18849MEDIUM5.5In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message ...
CVE-2019-18841HIGH7.3Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.
CVE-2019-18836HIGH7.5Envoy 1.12.0 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connectio...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now