2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17115MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote atta...
CVE-2019-17114MEDIUM6.1A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow...
CVE-2019-16917HIGH8.8WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection th...
CVE-2019-14287HIGH8.8In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se...
CVE-2019-13411CRITICAL9.8An “invalid command” handler issue was discovered in HiNet GPON firmware < I040GWR190731. It allows an attacker to execu...
CVE-2019-11284HIGH8.6Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remot...
CVE-2019-16330MEDIUM5.4In NCH Express Accounts Accounting v7.02, persistent cross site scripting (XSS) exists in Invoices/Sales Orders/Items/Cu...
CVE-2019-11253HIGH7.5Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1...
CVE-2019-15850HIGH8.8eQ-3 HomeMatic CCU3 firmware version 3.41.11 allows Remote Code Execution in the ReGa.runScript method. An authenticated...
CVE-2019-15849HIGH7.3eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs and send them to the vi...
CVE-2019-14424MEDIUM6.5A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6...
CVE-2019-14423HIGH8.8A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45....
CVE-2019-17676HIGH8.8app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup...
CVE-2019-17675HIGH8.8WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, po...
CVE-2019-17674MEDIUM5.4WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17673HIGH7.5WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary...
CVE-2019-17672MEDIUM6.1WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17671MEDIUM5.3In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m...
CVE-2019-17670CRITICAL9.8WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled durin...
CVE-2019-17669CRITICAL9.8WordPress before 5.2.4 has a Server Side Request Forgery (SSRF) vulnerability because URL validation does not consider t...
CVE-2019-17668MEDIUM6.8Samsung Galaxy S10 and Note10 devices allow unlock operations via unregistered fingerprints in certain situations involv...
CVE-2019-17667MEDIUM5.4Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.
CVE-2019-17666HIGH8.8rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-boun...
CVE-2019-17611MEDIUM6.1HongCMS 3.0.0 has XSS via the install/index.php tableprefix parameter.
CVE-2019-17610MEDIUM6.1HongCMS 3.0.0 has XSS via the install/index.php dbpassword parameter.

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now