2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-16988MEDIUM6.1In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" ...
CVE-2019-16987MEDIUM6.1In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming f...
CVE-2019-16986MEDIUM6.5In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which t...
CVE-2019-16985MEDIUM6.5In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the UR...
CVE-2019-16984MEDIUM6.1In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming fro...
CVE-2019-16983MEDIUM6.1In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface...
CVE-2019-16982MEDIUM6.1In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable comin...
CVE-2019-16981MEDIUM6.1In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" varia...
CVE-2019-16990MEDIUM6.5In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from ...
CVE-2019-16980HIGH8.8In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming ...
CVE-2019-16979MEDIUM6.1In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL,...
CVE-2019-16978MEDIUM6.1In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the UR...
CVE-2019-16530HIGH7.2Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execu...
CVE-2019-18218HIGH7.8cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a...
CVE-2019-18217HIGH7.5ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handl...
CVE-2019-17409MEDIUM6.1Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
CVE-2019-16862MEDIUM6.1Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbi...
CVE-2019-10716HIGH7.7An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se...
CVE-2019-10715MEDIUM5.4There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Seque...
CVE-2019-18216MEDIUM6.8The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of...
CVE-2019-18214HIGH7.7The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurren...
CVE-2019-18209MEDIUM6.1templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated ...
CVE-2019-18202MEDIUM5.3Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. ...
CVE-2019-18198HIGH7.8In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppres...
CVE-2019-18197HIGH7.5In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the rel...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now