2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-6144MEDIUM6.5This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08...
CVE-2019-3982MEDIUM6.5Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of ...
CVE-2019-18357MEDIUM6.1An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 2 of 2).
CVE-2019-18356MEDIUM6.1An XSS issue was discovered in Thycotic Secret Server before 10.7 (issue 1 of 2).
CVE-2019-18355CRITICAL9.8An SSRF issue was discovered in the legacy Web launcher in Thycotic Secret Server before 10.7.
CVE-2019-18350MEDIUM6.1In Ant Design Pro 4.0.0, reflected XSS in the user/login redirect GET parameter affects the authorization component, lea...
CVE-2019-18348MEDIUM6.1An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection i...
CVE-2019-17606MEDIUM6.1The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XS...
CVE-2019-17093HIGH7.8An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability all...
CVE-2019-16977MEDIUM6.1In FusionPBX up to 4.5.7, the file app\extensions\extension_imports.php uses an unsanitized "query_string" variable comi...
CVE-2019-16975MEDIUM6.1In FusionPBX up to 4.5.7, the file app\contacts\contact_notes.php uses an unsanitized "id" variable coming from the URL,...
CVE-2019-11933CRITICAL9.8A heap buffer overflow bug in libpl_droidsonroids_gif before 1.2.19, as used in WhatsApp for Android before version 2.19...
CVE-2019-11283HIGH8.8Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote use...
CVE-2019-11282MEDIUM4.3Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote...
CVE-2019-18344CRITICAL9.8Sourcecodester Online Grading System 1.0 is vulnerable to unauthenticated SQL injection and can allow remote attackers t...
CVE-2019-18281MEDIUM4.3An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12...
CVE-2019-16976MEDIUM6.1In FusionPBX up to 4.5.7, the file app\destinations\destination_imports.php uses an unsanitized "query_string" variable ...
CVE-2019-18280HIGH8.8Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF...
CVE-2019-18278HIGH7.8When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow st...
CVE-2019-18277HIGH7.5A flaw was found in HAProxy before 2.0.6. In legacy mode, messages featuring a transfer-encoding header missing the "chu...
CVE-2019-18220HIGH8.8Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to valid...
CVE-2019-18219MEDIUM6.1Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The a...
CVE-2019-10476HIGH7.8Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ma...
CVE-2019-10475MEDIUM6.1A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML...
CVE-2019-10474MEDIUM4.3A missing permission check in Jenkins Global Post Script Plugin in allowed users with Overall/Read access to list the sc...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now