2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-4523 | HIGH | 7.8 | 0.4% | Oct 22, 2019 | IBM DB2 High Performance Unload load for LUW 6.1 and 6.5 is vulnerable to a buffer overflow, caused by improper bounds c... |
| CVE-2019-17189 | MEDIUM | 5.4 | 0.8% | Oct 22, 2019 | totemodata 3.0.0_b936 has XSS via a folder name. |
| CVE-2019-12967 | MEDIUM | 6.5 | 1.0% | Oct 22, 2019 | Stephan Mooltipass Moolticute through 0.42.1 (and possibly earlier versions) has Incorrect Access Control. |
| CVE-2019-11674 | MEDIUM | 5.9 | 0.4% | Oct 22, 2019 | Man-in-the-middle vulnerability in Micro Focus Self Service Password Reset, affecting all versions prior to 4.4.0.4. The... |
| CVE-2019-17424 | HIGH | 7.8 | 13.4% | Oct 22, 2019 | A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re... |
| CVE-2019-17400 | HIGH | 7.5 | 1.9% | Oct 21, 2019 | The unoconv package before 0.9 mishandles untrusted pathnames, leading to SSRF and local file inclusion. |
| CVE-2019-16404 | HIGH | 8.8 | 1.1% | Oct 21, 2019 | Authenticated SQL Injection in interface/forms/eye_mag/js/eye_base.php in OpenEMR through 5.0.2 allows a user to extract... |
| CVE-2019-17498 | HIGH | 8.1 | 3.8% | Oct 21, 2019 | In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds che... |
| CVE-2019-17220 | MEDIUM | 6.1 | 4.0% | Oct 21, 2019 | Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line. |
| CVE-2019-16974 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\contacts\contact_times.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-16969 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\fifo_list\fifo_interactive.php uses an unsanitized "c" variable coming from the U... |
| CVE-2019-16970 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to 4.5.7, the file app\sip_status\sip_status.php uses an unsanitized "savemsg" variable coming from the ... |
| CVE-2019-16968 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | An issue was discovered in FusionPBX up to 4.5.7. In the file app\conference_controls\conference_control_details.php, an... |
| CVE-2019-16967 | MEDIUM | 6.1 | 1.3% | Oct 21, 2019 | An issue was discovered in Manager 13.x before 13.0.2.6 and 15.x before 15.0.6 before FreePBX 14.0.10.3. In the Manager ... |
| CVE-2019-9491 | HIGH | 7.8 | 12.9% | Oct 21, 2019 | Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to... |
| CVE-2019-16966 | MEDIUM | 6.1 | 1.1% | Oct 21, 2019 | An issue was discovered in Contactmanager 13.x before 13.0.45.3, 14.x before 14.0.5.12, and 15.x before 15.0.8.21 for Fr... |
| CVE-2019-16965 | HIGH | 7.2 | 3.0% | Oct 21, 2019 | resources/cmd.php in FusionPBX up to 4.5.7 suffers from a command injection vulnerability due to a lack of input validat... |
| CVE-2019-16964 | HIGH | 8.8 | 2.0% | Oct 21, 2019 | app/call_centers/cmd.php in the Call Center Queue Module in FusionPBX up to 4.5.7 suffers from a command injection vulne... |
| CVE-2019-8370 | — | — | — | Oct 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2019-18225 | CRITICAL | 9.8 | 1.5% | Oct 21, 2019 | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway before 10.5 build 70.8, 11.x before ... |
| CVE-2019-18203 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | On the RICOH MP 501 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding ad... |
| CVE-2019-8369 | — | — | — | Oct 21, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2019-18224 | CRITICAL | 9.8 | 3.7% | Oct 21, 2019 | idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. |
| CVE-2019-16991 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\edit\filedelete.php uses an unsanitized "file" variable coming from the URL, whi... |
| CVE-2019-16989 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\conferences_active\conference_interactive.php uses an unsanitized "c" variable c... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now