2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-16988 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\basic_operator_panel\resources\content.php uses an unsanitized "eavesdrop_dest" ... |
| CVE-2019-16987 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\contacts\contact_import.php uses an unsanitized "query_string" variable coming f... |
| CVE-2019-16986 | MEDIUM | 6.5 | 1.4% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file resources\download.php uses an unsanitized "f" variable coming from the URL, which t... |
| CVE-2019-16985 | MEDIUM | 6.5 | 1.1% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\xml_cdr\xml_cdr_delete.php uses an unsanitized "rec" variable coming from the UR... |
| CVE-2019-16984 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\recordings\recording_play.php uses an unsanitized "filename" variable coming fro... |
| CVE-2019-16983 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file resources\paging.php has a paging function (called by several pages of the interface... |
| CVE-2019-16982 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\access_controls\access_control_nodes.php uses an unsanitized "id" variable comin... |
| CVE-2019-16981 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\conference_profiles\conference_profile_params.php uses an unsanitized "id" varia... |
| CVE-2019-16990 | MEDIUM | 6.5 | 1.3% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app/music_on_hold/music_on_hold.php uses an unsanitized "file" variable coming from ... |
| CVE-2019-16980 | HIGH | 8.8 | 1.2% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\call_broadcast\call_broadcast_edit.php uses an unsanitized "id" variable coming ... |
| CVE-2019-16979 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\contacts\contact_urls.php uses an unsanitized "id" variable coming from the URL,... |
| CVE-2019-16978 | MEDIUM | 6.1 | 0.9% | Oct 21, 2019 | In FusionPBX up to v4.5.7, the file app\devices\device_settings.php uses an unsanitized "id" variable coming from the UR... |
| CVE-2019-16530 | HIGH | 7.2 | 3.3% | Oct 21, 2019 | Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execu... |
| CVE-2019-18218 | HIGH | 7.8 | 1.8% | Oct 21, 2019 | cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a... |
| CVE-2019-18217 | HIGH | 7.5 | 19.5% | Oct 21, 2019 | ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handl... |
| CVE-2019-17409 | MEDIUM | 6.1 | 0.8% | Oct 21, 2019 | Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter. |
| CVE-2019-16862 | MEDIUM | 6.1 | 1.5% | Oct 21, 2019 | Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbi... |
| CVE-2019-10716 | HIGH | 7.7 | 4.1% | Oct 21, 2019 | An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se... |
| CVE-2019-10715 | MEDIUM | 5.4 | 0.5% | Oct 21, 2019 | There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Seque... |
| CVE-2019-18216 | MEDIUM | 6.8 | 0.4% | Oct 20, 2019 | The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of... |
| CVE-2019-18214 | HIGH | 7.7 | 1.4% | Oct 19, 2019 | The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurren... |
| CVE-2019-18209 | MEDIUM | 6.1 | 0.7% | Oct 19, 2019 | templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated ... |
| CVE-2019-18202 | MEDIUM | 5.3 | 1.8% | Oct 19, 2019 | Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. ... |
| CVE-2019-18198 | HIGH | 7.8 | 0.5% | Oct 18, 2019 | In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppres... |
| CVE-2019-18197 | HIGH | 7.5 | 4.4% | Oct 18, 2019 | In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the rel... |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now