2019 CVE Vulnerabilities

17,621 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-18420MEDIUM6.5An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_i...
CVE-2019-17551MEDIUM6.1In Apak Wholesale Floorplanning Finance 6.31.8.3 and 6.31.8.5, an attacker can send an authenticated POST request with a...
CVE-2019-18645MEDIUM5.5The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowi...
CVE-2019-18644MEDIUM5.9The malware scan function in Total Defense Anti-virus 11.5.2.28 is vulnerable to a TOCTOU bug; consequently, symbolic li...
CVE-2019-18635HIGH7.5An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a...
CVE-2019-18633CRITICAL9.8European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain Exp...
CVE-2019-18632CRITICAL9.8European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a...
CVE-2019-12417MEDIUM4.8A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript ...
CVE-2019-10762CRITICAL9.8columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.
CVE-2019-17326MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET r...
CVE-2019-17325MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX met...
CVE-2019-17324MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with .....
CVE-2019-17323HIGH8.8ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of...
CVE-2019-17322MEDIUM6.5ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set ...
CVE-2019-17321MEDIUM5.3ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated...
CVE-2019-18207MEDIUM5.4In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper ...
CVE-2019-18206HIGH8.8A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary ...
CVE-2019-18205MEDIUM6.1Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1...
CVE-2019-18204HIGH8.8Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve...
CVE-2019-15682HIGH7.5RDesktop version 1.8.4 contains multiple out-of-bound access read vulnerabilities in its code, which results in a denial...
CVE-2019-7620HIGH7.5Logstash versions before 7.4.1 and 6.8.4 contain a denial of service flaw in the Logstash Beats input plugin. An unauthe...
CVE-2019-7619MEDIUM5.3Elasticsearch versions 7.0.0-7.3.2 and 6.7.0-6.8.3 contain a username disclosure flaw was found in the API Key service. ...
CVE-2019-8235MEDIUM6.5An insecure direct object reference (IDOR) vulnerability exists in Magento 2.3 prior to 2.3.1, 2.2 prior to 2.2.8, and 2...
CVE-2019-9926HIGH8.8An issue was discovered in LabKey Server 19.1.0. It is possible to force a logged-in administrator to execute code throu...
CVE-2019-9758MEDIUM5.4An issue was discovered in LabKey Server 19.1.0. The display name of a user is vulnerable to stored XSS that can execute...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now