2019 CVE Vulnerabilities
17,623 CVEs published in 2019.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2019-17115 | MEDIUM | 6.1 | 1.7% | Oct 17, 2019 | Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote atta... |
| CVE-2019-17114 | MEDIUM | 6.1 | 1.7% | Oct 17, 2019 | A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow... |
| CVE-2019-16917 | HIGH | 8.8 | 2.1% | Oct 17, 2019 | WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection th... |
| CVE-2019-14287 | HIGH | 8.8 | 63.9% | Oct 17, 2019 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se... |
| CVE-2019-13411 | CRITICAL | 9.8 | 1.3% | Oct 17, 2019 | An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execu... |
| CVE-2019-11284 | HIGH | 8.6 | 0.9% | Oct 17, 2019 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remot... |
| CVE-2019-16330 | MEDIUM | 5.4 | 0.6% | Oct 17, 2019 | In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Cu... |
| CVE-2019-11253 | HIGH | 7.5 | 25.9% | Oct 17, 2019 | Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1... |
| CVE-2019-15850 | HIGH | 8.8 | 15.6% | Oct 17, 2019 | eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated... |
| CVE-2019-15849 | HIGH | 7.3 | 0.8% | Oct 17, 2019 | eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the vi... |
| CVE-2019-14424 | MEDIUM | 6.5 | 1.4% | Oct 17, 2019 | A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6... |
| CVE-2019-14423 | HIGH | 8.8 | 19.9% | Oct 17, 2019 | A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.... |
| CVE-2019-17676 | HIGH | 8.8 | 0.6% | Oct 17, 2019 | app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup... |
| CVE-2019-17675 | HIGH | 8.8 | 2.8% | Oct 17, 2019 | WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, po... |
| CVE-2019-17674 | MEDIUM | 5.4 | 1.6% | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer. |
| CVE-2019-17673 | HIGH | 7.5 | 3.2% | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary... |
| CVE-2019-17672 | MEDIUM | 6.1 | 1.8% | Oct 17, 2019 | WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements. |
| CVE-2019-17671 | MEDIUM | 5.3 | 36.5% | Oct 17, 2019 | In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m... |
| CVE-2019-17670 | CRITICAL | 9.8 | 4.5% | Oct 17, 2019 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled durin... |
| CVE-2019-17669 | CRITICAL | 9.8 | 5.2% | Oct 17, 2019 | WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider t... |
| CVE-2019-17668 | MEDIUM | 6.8 | 0.4% | Oct 17, 2019 | Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involv... |
| CVE-2019-17667 | MEDIUM | 5.4 | 0.5% | Oct 17, 2019 | Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field. |
| CVE-2019-17666 | HIGH | 8.8 | 3.0% | Oct 17, 2019 | rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-boun... |
| CVE-2019-17611 | MEDIUM | 6.1 | 1.0% | Oct 16, 2019 | HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter. |
| CVE-2019-17610 | MEDIUM | 6.1 | 1.0% | Oct 16, 2019 | HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter. |
Check if your code is affected by 2019 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now