2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-8078MEDIUM6.1Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful explo...
CVE-2019-18417HIGH8.8Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can resu...
CVE-2019-18416MEDIUM6.1Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.
CVE-2019-18415MEDIUM6.1Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.
CVE-2019-18414HIGH8.8Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulner...
CVE-2019-18413CRITICAL9.8In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can...
CVE-2019-12095HIGH8.8Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated ...
CVE-2019-12094MEDIUM6.1Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.p...
CVE-2019-9699MEDIUM4.5Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of ...
CVE-2019-5013HIGH7.8An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in...
CVE-2019-5012HIGH7.8An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in...
CVE-2019-18196MEDIUM6.7A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),...
CVE-2019-15929CRITICAL9.8In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, lea...
CVE-2019-11021HIGH7.2admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execu...
CVE-2019-18201HIGH7.5An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o...
CVE-2019-18200CRITICAL9.8An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o...
CVE-2019-13653CRITICAL9.8TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).
CVE-2019-13652CRITICAL9.8TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).
CVE-2019-13651CRITICAL9.8TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5...
CVE-2019-13650CRITICAL9.8TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5).
CVE-2019-13649CRITICAL9.8TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).
CVE-2019-12017CRITICAL9.8A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the C...
CVE-2019-6692HIGH7.8A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker t...
CVE-2019-18409HIGH7.8The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files...
CVE-2019-18408HIGH7.5archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free i...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now