2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-8078 | MEDIUM | 6.1 | 1.6% | Oct 24, 2019 | Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a reflected cross site scripting vulnerability. Successful explo... |
| CVE-2019-18417 | HIGH | 8.8 | 1.7% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can resu... |
| CVE-2019-18416 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member. |
| CVE-2019-18415 | MEDIUM | 6.1 | 0.7% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen. |
| CVE-2019-18414 | HIGH | 8.8 | 0.5% | Oct 24, 2019 | Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulner... |
| CVE-2019-18413 | CRITICAL | 9.8 | 2.0% | Oct 24, 2019 | In TypeStack class-validator 0.10.2, validate() input validation can be bypassed because certain internal attributes can... |
| CVE-2019-12095 | HIGH | 8.8 | 1.1% | Oct 24, 2019 | Horde Trean, as used in Horde Groupware Webmail Edition through 5.2.22 and other products, allows CSRF, as demonstrated ... |
| CVE-2019-12094 | MEDIUM | 6.1 | 1.5% | Oct 24, 2019 | Horde Groupware Webmail Edition through 5.2.22 allows XSS via an admin/user.php?form=update_f&user_name= or admin/user.p... |
| CVE-2019-9699 | MEDIUM | 4.5 | 0.5% | Oct 24, 2019 | Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of ... |
| CVE-2019-5013 | HIGH | 7.8 | 0.6% | Oct 24, 2019 | An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in... |
| CVE-2019-5012 | HIGH | 7.8 | 0.5% | Oct 24, 2019 | An exploitable privilege escalation vulnerability exists in the Wacom, driver version 6.3.32-3, update helper service in... |
| CVE-2019-18196 | MEDIUM | 6.7 | 0.6% | Oct 24, 2019 | A DLL side loading vulnerability in the Windows Service in TeamViewer versions up to 11.0.133222 (fixed in 11.0.214397),... |
| CVE-2019-15929 | CRITICAL | 9.8 | 1.6% | Oct 24, 2019 | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, lea... |
| CVE-2019-11021 | HIGH | 7.2 | 2.2% | Oct 24, 2019 | admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execu... |
| CVE-2019-18201 | HIGH | 7.5 | 1.2% | Oct 24, 2019 | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o... |
| CVE-2019-18200 | CRITICAL | 9.8 | 2.8% | Oct 24, 2019 | An issue was discovered on Fujitsu Wireless Keyboard Set LX390 GK381 devices. Because of the lack of proper encryption o... |
| CVE-2019-13653 | CRITICAL | 9.8 | 2.1% | Oct 24, 2019 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5). |
| CVE-2019-13652 | CRITICAL | 9.8 | 2.8% | Oct 24, 2019 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5). |
| CVE-2019-13651 | CRITICAL | 9.8 | 3.0% | Oct 24, 2019 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5... |
| CVE-2019-13650 | CRITICAL | 9.8 | 2.8% | Oct 24, 2019 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5). |
| CVE-2019-13649 | CRITICAL | 9.8 | 2.8% | Oct 24, 2019 | TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5). |
| CVE-2019-12017 | CRITICAL | 9.8 | 2.9% | Oct 24, 2019 | A remote code execution vulnerability exists in MapR CLDB code, specifically in the JSON framework that is used in the C... |
| CVE-2019-6692 | HIGH | 7.8 | 0.5% | Oct 24, 2019 | A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker t... |
| CVE-2019-18409 | HIGH | 7.8 | 0.3% | Oct 24, 2019 | The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files... |
| CVE-2019-18408 | HIGH | 7.5 | 4.0% | Oct 24, 2019 | archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free i... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now