2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-2110MEDIUM5.5In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a miss...
CVE-2019-6335HIGH7.5A potential security vulnerability has been identified with Samsung Laser Printers. This vulnerability could potentially...
CVE-2019-14570HIGH7.8Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of pr...
CVE-2019-14569HIGH7.8Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of p...
CVE-2019-11167HIGH7.8Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authe...
CVE-2019-11120HIGH7.8Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an ...
CVE-2019-6333MEDIUM6.7A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version...
CVE-2019-17504MEDIUM6.1An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln...
CVE-2019-17503MEDIUM5.3An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG...
CVE-2019-17059CRITICAL9.8A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remo...
CVE-2019-14510MEDIUM6.7An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature ...
CVE-2019-17499HIGH8.8The setter.xml component of the Common Gateway Interface on Compal CH7465LG 6.12.18.25-2p4 devices does not properly val...
CVE-2019-17497MEDIUM6.5Tracker PDF-XChange Editor before 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a ...
CVE-2019-17496MEDIUM6.1Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
CVE-2019-17495CRITICAL9.8A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative...
CVE-2019-17494MEDIUM6.1laravel-bjyblog 6.1.1 has XSS via a crafted URL.
CVE-2019-17493MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[sample_input] parameter to web/admin/problem/create or we...
CVE-2019-17491MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[description] parameter to web/admin/problem/create or web...
CVE-2019-17490HIGH8.8app\modules\polygon\controllers\ProblemController in Jiangnan Online Judge (aka jnoj) 0.8.0 allows arbitrary file upload...
CVE-2019-17489MEDIUM6.1Jiangnan Online Judge (aka jnoj) 0.8.0 has XSS via the Problem[title] parameter to web/polygon/problem/create or web/pol...
CVE-2019-17488MEDIUM6.1b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
CVE-2019-17386HIGH8.8The animate-it plugin before 2.3.6 for WordPress has CSRF in edsanimate.php.
CVE-2019-9534HIGH7.8The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the fi...
CVE-2019-9533CRITICAL9.8The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08. This co...
CVE-2019-9532HIGH7.8The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. Thi...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now