2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-1166MEDIUM5.9A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass t...
CVE-2019-1070MEDIUM5.4A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall...
CVE-2019-1060HIGH8.8A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka...
CVE-2019-13929MEDIUM6.5A vulnerability has been identified in SIMATIC IT UADM (All versions < V1.3). An authenticated remote attacker with netw...
CVE-2019-13921HIGH7.5A vulnerability has been identified in SIMATIC WinAC RTX (F) 2010 (All versions < SP3 Update 1). Affected versions of th...
CVE-2019-10936HIGH7.5Affected devices improperly handle large amounts of specially crafted UDP packets. This could allow an unauthenticate...
CVE-2019-10923HIGH7.5An attacker with network access to an affected product may cause a denial of service condition by breaking the real-time...
CVE-2019-0608MEDIUM4.3A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spo...
CVE-2019-17434MEDIUM5.4LavaLite through 5.7 has XSS via a crafted account name that is mishandled on the Manage Clients screen.
CVE-2019-17433MEDIUM4.8z-song laravel-admin 1.7.3 has XSS via the Slug or Name on the Roles screen, because of mishandling on the "Operation lo...
CVE-2019-17432MEDIUM6.5An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/admin/general.config/edit CSRF vulnerability...
CVE-2019-17431HIGH8.8An issue was discovered in fastadmin 1.0.0.20190705_beta. There is a public/index.php/admin/auth/admin/add CSRF vulnerab...
CVE-2019-17430MEDIUM6.1EyouCms through 2019-07-11 has XSS related to the login.php web_recordnum parameter.
CVE-2019-17429CRITICAL9.8Adhouma CMS through 2019-10-09 has SQL Injection via the post.php p_id parameter.
CVE-2019-17072CRITICAL9.8The new-contact-form-widget (aka Contact Form Widget - Contact Query, Form Maker) plugin 1.0.9 for WordPress has SQL Inj...
CVE-2019-17071MEDIUM6.1The client-dash (aka Client Dash) plugin 2.1.4 for WordPress allows XSS.
CVE-2019-17070MEDIUM6.1The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explore...
CVE-2019-17427MEDIUM6.1In Redmine before 3.4.11 and 4.0.x before 4.0.4, persistent XSS exists due to textile formatting errors.
CVE-2019-17426CRITICAL9.1Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query obj...
CVE-2019-17420MEDIUM5.3In OISF LibHTP before 0.5.31, as used in Suricata 4.1.4 and other products, an HTTP protocol parsing error causes the ht...
CVE-2019-17419HIGH7.2An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=user&c=admin_user&a=doGetUserInfo id par...
CVE-2019-17418HIGH7.2An issue was discovered in MetInfo 7.0. There is SQL injection via the admin/?n=language&c=language_general&a=doSearchPa...
CVE-2019-17417MEDIUM4.8PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-5700HIGH7.8NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it ...
CVE-2019-5699HIGH7.8NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software perform...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now