2019 CVE Vulnerabilities

17,623 CVEs published in 2019.

CVE IDSeverityCVSSDescription
CVE-2019-17376MEDIUM6.1cPanel before 82.0.15 allows self XSS in the SSL Certificate Upload interface (SEC-521).
CVE-2019-17375HIGH8.8cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
CVE-2019-17128HIGH7.5Netreo OmniCenter through 12.1.1 allows unauthenticated SQL Injection (Boolean Based Blind) in the redirect parameters a...
CVE-2019-17124CRITICAL9.8Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
CVE-2019-15859CRITICAL9.8Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get f...
CVE-2019-15226HIGH7.5Upon receiving each incoming request header data, Envoy will iterate over existing request headers to verify that the to...
CVE-2019-14808MEDIUM6.8An issue was discovered in the RENPHO application 3.0.0 for iOS. It transmits JSON data unencrypted to a server without ...
CVE-2019-13529HIGH8.8An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action...
CVE-2019-11341MEDIUM4.6On certain Samsung P(9.0) phones, an attacker with physical access can start a TCP Dump capture without the user's knowl...
CVE-2019-11212MEDIUM5.4The MDM server component of TIBCO Software Inc's TIBCO MDM contains multiple vulnerabilities that theoretically allow an...
CVE-2019-17382CRITICAL9.1An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass ...
CVE-2019-17373CRITICAL9.8Certain NETGEAR devices allow unauthenticated access to critical .cgi and .htm pages via a substring ending with .jpg, s...
CVE-2019-17372HIGH8.1Certain NETGEAR devices allow remote attackers to disable all authentication requirements by visiting genieDisableLanCha...
CVE-2019-17371MEDIUM6.5gif2png 2.5.13 has a memory leak in the writefile function.
CVE-2019-17370HIGH7.2OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT st...
CVE-2019-17354CRITICAL9.4wan.htm page on Zyxel NBG-418N v2 with firmware version V1.00(AARP.9)C0 can be accessed directly without authentication,...
CVE-2019-17353HIGH8.2An issue discovered on D-Link DIR-615 devices with firmware version 20.05 and 20.07. wan.htm can be accessed directly wi...
CVE-2019-15719HIGH8Altair PBS Professional through 19.1.2 allows Privilege Escalation because an attacker can send a message directly to pb...
CVE-2019-13051HIGH8.8Pi-Hole 4.3 allows Command Injection.
CVE-2019-17369MEDIUM6.5OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group accoun...
CVE-2019-17368MEDIUM6.1S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.
CVE-2019-17362CRITICAL9.1In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detec...
CVE-2019-3980CRITICAL9.8The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to...
CVE-2019-10757CRITICAL9.8knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of th...
CVE-2019-0381MEDIUM5.5A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before ve...

Check if your code is affected by 2019 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now